HAProxy
Automate TLS certificate enrollment and renewal on HAProxy with the Horizon Client.
The Horizon Client automates the full TLS certificate lifecycle on HAProxy. The certificate chain and private key are written to the file system and HAProxy is restarted automatically after each enrollment or renewal.
Prerequisites
- HAProxy installed and running
- Horizon Client installed and configured (see Installation & Configuration)
- A PKI connector configured in Horizon. See Configure SwissSign MPKI.
- A certificate profile configured in Horizon. See Certificate Profiles.
- An automation policy configured in Horizon. See Automation Policies.
- Root or sudo access on the server
Setting up TLS on a new HAProxy server
Use init when HAProxy does not yet have an HTTPS configuration:
sudo horizon-cli automate init --target=haproxy --automation-policy=<policy>To set up HTTPS on a non-standard port:
sudo horizon-cli automate init --target=haproxy --automation-policy=<policy> --port=<port>Taking control of an existing certificate
Use enroll when HAProxy is already serving HTTPS. The client detects the existing certificate from the HAProxy configuration, re-enrolls it under the automation policy, and updates the config:
sudo horizon-cli automate enroll --target=haproxy --automation-policy=<policy>To preview what the client finds without making any changes:
sudo horizon-cli automate enroll --target=haproxy --automation-policy=<policy> --analyze-onlyScheduled renewal
Once enrolled, run routine to check for and perform renewals:
sudo horizon-cli automate routineCreate a cron job to run this automatically:
sudo horizon-cli automate create-periodic-taskThe period can be any value between 1h and 24h. The default is 6h. To remove the cron job:
sudo horizon-cli automate remove-periodic-taskCertificate storage and backup
HAProxy expects the certificate chain and private key in a single combined file (PEM bundle) or as separate files, depending on your configuration. The Horizon Client detects the format from the existing HAProxy configuration and writes files accordingly. On each renewal:
- The new files replace the current ones.
- The previous files are backed up in
/opt/horizon/cert/backup/. - The original files from before Horizon took management are always preserved.
To see which certificates are currently managed and find their IDs:
horizon-cli automate listIDs follow the format <target>-*:<port>, for example haproxy-*:443.
To remove a certificate from Horizon management and restore the original, pass the ID from automate list:
sudo horizon-cli automate remove <id> --restoreFor trigger-based workflows and other advanced automation configuration, refer to the Evertrust Horizon documentation.