github avandeputte/haproxy-manager v1.90.0
1.90.0

latest releases: v1.95.0, v1.95.0-beta.1, v1.94.0...
one month ago

Everything since 1.85.2 — five features and the fixes they shook out.

Single sign-on for services (OIDC). Services can send their visitors through an identity provider — Authentik, Keycloak, Authelia, Pocket ID, Google, Entra — with a per-service allow-list of emails and @domains. One sign-in covers every protected service; authorization stays per service. What makes it fit a proxy: HAProxy itself verifies the session on every request, in generated configuration (an HMAC-signed cookie checked timing-safely, HAProxy 2.4+, no Lua) — the app only plays the sign-in dance on a dedicated auth host. The signing secret is shared configuration, so a failover signs nobody out, and Rotate secret signs everyone out at once. The session cookie is stripped before requests reach your servers; a per-service toggle can instead pass the verified identity as X-Auth-Request-Email/Remote-User for apps that sign proxy-identified visitors in themselves — with client-sent forgeries of those headers deleted on every service, forwarding or not. The settings page carries paste-ready setup steps for authentik, Authelia and Google, built from your real hostnames. Verified end-to-end against a live IdP: sign-in, deep-link return, stranger 403, forged-cookie redirect, cookie stripping, rotation.

Home Assistant, by MQTT discovery. Point Notifications → Home Assistant at your broker and the entities appear by themselves: a device per node (holds the virtual IP, HAProxy answering) and one for the cluster — a problem sensor per service that honours its Alert when setting, connectivity per published URL, days-to-expiry per certificate, drift, nodes reachable, requests per minute. Availability rides an MQTT will, so a dead node's entities grey out the moment it dies. Opt-in control: a maintenance switch per service, off by default because anyone who can publish to the broker holds that power.

Maintenance mode. Pause a service — every request answered with a clean 503 while the servers and their health checks stay untouched, so pausing never reads as an outage and resuming is instant. Pause/Resume on the Services page, a switch in the pool editor, the API, and (opted in) Home Assistant.

Two-factor sign-in for this UI. Optional TOTP for the management login: QR enrolment (drawn by our own encoder, verified module-for-module against reference implementations), recovery codes, replay protection, and a CLI escape hatch. The login's second step now survives the background pollers instead of vanishing mid-type.

Metrics for Prometheus. GET /metrics behind the node's API key: per-pool requests and errors, servers up, certificate expiries (and whether a file is still the self-signed stand-in), probe verdicts, cluster agreement, watchdog state. Scrape every node; ham_node_active says which one holds the virtual IP.

Raw haproxy.cfg, per object. Every editor under Advanced · HAProxy carries a second tab showing exactly what Apply will write for that object — recomputed from the form as it stands, so an edit can be read before it is committed.

Also: unverified email claims are refused by default with an explicit override for providers that cannot say verified (Keycloak users: tick Email verified instead); metric families render as one group each, as the stricter parsers demand; the hidden attribute always wins over page CSS.

Upgrading: nothing breaks. SSO sessions issued before 1.90.0 re-issue silently on the next visit.

Packages are attached below; the container image is at ghcr.io/avandeputte/haproxy-manager:1.90.0.

Don't miss a new haproxy-manager release

NewReleases is sending notifications on new releases.