1·重新编译haproxy并加上openssl,可以参考https://www.jianshu.com/p/34b5a5233f8f?from=singlemessage
2.使用ssl穿透,在负载均衡的后端机器上分别配置https并修改/etc/haproxy/haproxy.cfg
添加如下配置:
frontend https_frontend
bind *:8878 #需要负载的https端口
mode tcp #模式
default_backend web_server #别名
backend web_server
mode tcp
balance roundrobin
stick-table type ip size 200k expire 30m
stick on src #目标主机
server s1 10.191.200.133:8878 maxconn 80000 check inter 5000 rise 3 fall 3 weight 1
server s2 10.191.200.134:8878 maxconn 80000 check inter 5000 rise 3 fall 3 weight 1
server s3 10.191.200.135:8878 maxconn 80000 check inter 5000 rise 3 fall 3 weight 1