Skip to main content
Version: 1.0.0

HAProxy on Aruba Cloud

Deploy HAProxy — a high-performance TCP/HTTP load balancer and proxy — on Aruba Cloud using Terraform and cloud-init. Backend servers are configured directly as a Terraform variable, making it easy to wire HAProxy in front of other examples in this repository.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

HAProxy is the de-facto standard open-source load balancer for high-availability web applications. This example provisions:

  • HAProxy installed from Ubuntu 22.04 packages
  • HTTP frontend on port 80 with configurable round-robin backends
  • Stats page on port 8404 (restricted to admin_cidr) with password auth
  • Backend servers supplied via the backends Terraform variable — add or remove servers with terraform apply

No backends? Deploy without backends and a local nginx demo server is installed automatically on 127.0.0.1:8080. HAProxy proxies to it so port 80 returns a real response. Add your own backend IPs later by updating backends and re-applying — the demo nginx is not installed when real backends are configured.


Architecture Overview​


Infrastructure Created​

ResourceName patternDescription
arubacloud_projecthaproxy-prodProject container
arubacloud_vpchaproxy-prod-vpcVirtual Private Cloud
arubacloud_subnethaproxy-prod-subnetBasic subnet
arubacloud_securitygrouphaproxy-prod-vm-sgSecurity group
arubacloud_securityrulehaproxy-prod-vm-sshSSH ingress
arubacloud_securityrulehaproxy-prod-vm-httpHTTP ingress TCP 80
arubacloud_securityrulehaproxy-prod-vm-statsStats page TCP 8404
arubacloud_elasticiphaproxy-prod-vm-eipVM public IP
arubacloud_blockstoragehaproxy-prod-boot20 GB boot disk (Performance)
arubacloud_keypairhaproxy-prod-keypairSSH public key
arubacloud_cloudserverhaproxy-prod-vmCloudServer VM

Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO2A4 — 2 vCPU / 4 GB~€18
Boot disk20 GB Performance~€3
Elastic IP—~€3
Total~€24/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • An ArubaCloud account with OAuth2 API credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content
stats_passwordPassword for HAProxy stats page (username: admin)

Optional​

VariableDefaultDescription
app_name"haproxy"Short name used in all resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
billing_period"Hour""Hour" or "Month"
vm_flavor"CSO2A4"CloudServer flavor
vm_image"LU22-001"Boot disk image (Ubuntu 22.04 LTS)
vm_disk_size_gb20Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH
web_cidr"0.0.0.0/0"CIDR for HTTP frontend port 80
admin_cidr"0.0.0.0/0"CIDR for stats page port 8404 — restrict in production
backends[]Backend server list in host:port format

Outputs​

OutputDescription
proxy_urlHAProxy HTTP frontend URL
stats_urlHAProxy stats page URL
vm_public_ipPublic IP address of the VM
ssh_commandSSH command to connect to the VM

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/haproxy

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars

Set the stats password and optionally your backend servers:

stats_password = "your-stats-password"
backends = ["10.0.0.1:80", "10.0.0.2:80"]

3. Deploy​

terraform init
terraform plan
terraform apply

Bootstrap takes approximately 1–2 minutes.

4. Access the stats page​

terraform output stats_url

Log in with admin / stats_password to view live connection counts, traffic rates, and backend health.

5. Add or remove backends​

Update the backends variable and re-apply — no VM restart needed:

# terraform.tfvars
backends = ["10.0.0.1:80", "10.0.0.2:80", "10.0.0.3:80"]
terraform apply

HAProxy reloads gracefully without dropping active connections.


Security Recommendations​

  1. Restrict admin_cidr to your management IP. The stats page exposes server IPs, connection counts, and configuration details.

  2. Use HTTPS for production. Pair HAProxy with a TLS terminator (e.g., Caddy or NGINX in front) or configure HAProxy to terminate SSL directly using a certificate in /etc/ssl/.


Troubleshooting​

HAProxy not starting​

sudo haproxy -c -f /etc/haproxy/haproxy.cfg # config check
sudo systemctl status haproxy
sudo journalctl -u haproxy -n 30

Backend servers showing DOWN in stats​

HAProxy performs GET / health checks on each backend. Ensure:

  • Backends are reachable from the HAProxy VM on the configured port
  • The backend HTTP server returns 2xx on GET /

Check connectivity:

curl -sv http://<backend-ip>:<port>/

Port 80 returns 503 after re-apply with real backends​

If you previously deployed without backends (demo nginx was installed) and then added real backends, the VM needs to be reprovisioned — terraform apply re-renders the cloud-init but the existing VM is not re-bootstrapped. Destroy and re-apply to get a clean build:

terraform destroy
terraform apply

References​