1·重新编译haproxy并加上openssl,可以参考​​https://www.jianshu.com/p/34b5a5233f8f?from=singlemessage​

2.使用ssl穿透,在负载均衡的后端机器上分别配置https并修改/etc/haproxy/haproxy.cfg

添加如下配置:

frontend https_frontend

bind *:8878    #需要负载的https端口

mode tcp  #模式

default_backend web_server #别名

backend web_server

mode tcp

balance roundrobin

stick-table type ip size 200k expire 30m

stick on src #目标主机

server s1 10.191.200.133:8878 maxconn 80000 check inter 5000 rise  3 fall  3  weight 1

server s2 10.191.200.134:8878 maxconn 80000 check inter 5000 rise  3 fall  3  weight 1

server s3 10.191.200.135:8878 maxconn 80000 check inter 5000 rise  3 fall  3  weight 1