--- title: "3. Global Section" linkTitle: "3. Global Section" weight: 140 description: "Process security, performance tuning, debugging, and HTTP client settings" icon: fa-solid fa-earth-americas module: [HAPROXY] categories: [Reference] aliases: - /haproxy/configuration/global/ - /docs/haproxy/configuration/global/ - /haproxy/global/ upstream_link: "https://docs.haproxy.org/3.4/configuration.html" upstream_name: "HAProxy 3.4 Configuration Manual" upstream_ref: "v3.4.4, chapter 3" --- Parameters in the "global" section are process-wide and often OS-specific. They are generally set once for all and do not need being changed once correct. Some of them have command-line equivalents. The following keywords are supported in the "global" section: - Process management and security - 51degrees-allow-unmatched - 51degrees-cache-size - 51degrees-data-file - 51degrees-difference - 51degrees-drift - 51degrees-property-name-list - 51degrees-property-separator - 51degrees-use-performance-graph - 51degrees-use-predictive-graph - ca-base - chroot - cluster-secret - cpu-affinity - cpu-map - cpu-policy - cpu-set - crt-base - daemon - default-path - description - deviceatlas-json-file - deviceatlas-log-level - deviceatlas-properties-cookie - deviceatlas-separator - dns-accept-family - expose-deprecated-directives - expose-experimental-directives - external-check - fd-hard-limit - gid - grace - group - h1-accept-payload-with-any-method - h1-case-adjust - h1-case-adjust-file - h1-do-not-close-on-insecure-transfer-encoding - h2-workaround-bogus-websocket-clients - hard-stop-after - harden.reject-privileged-ports.tcp - harden.reject-privileged-ports.quic - insecure-fork-wanted - insecure-setuid-wanted - issuers-chain-path - jwt.decrypt_alg_list - jwt.decrypt_enc_list - key-base - limited-quic - localpeer - log - log-send-hostname - log-tag - lua-load - lua-load-per-thread - lua-prepend-path - max-threads-per-group - mworker-max-reloads - nbthread - node - numa-cpu-mapping - ocsp-update.disable - ocsp-update.maxdelay - ocsp-update.mindelay - ocsp-update.httpproxy - ocsp-update.mode - pidfile - pp2-never-send-local - presetenv - prealloc-fd - resetenv - set-dumpable - set-var - setenv - ssl-default-bind-ciphers - ssl-default-bind-ciphersuites - ssl-default-bind-client-sigalgs - ssl-default-bind-curves - ssl-default-bind-options - ssl-default-bind-sigalgs - ssl-default-server-ciphers - ssl-default-server-ciphersuites - ssl-default-server-client-sigalgs - ssl-default-server-curves - ssl-default-server-options - ssl-default-server-sigalgs - ssl-dh-param-file - ssl-propquery - ssl-provider - ssl-provider-path - ssl-security-level - ssl-server-verify - ssl-skip-self-issued-ca - stats - stats-file - strict-limits - uid - ulimit-n - unix-bind - unsetenv - user - wurfl-cache-size - wurfl-data-file - wurfl-information-list - wurfl-information-list-separator - Performance tuning - busy-polling - max-spread-checks - maxcompcpuusage - maxcomprate - maxconn - maxconnrate - maxpipes - maxsessrate - maxsslconn - maxsslrate - maxzlibmem - no-memory-trimming - noepoll - noevports - nogetaddrinfo - nokqueue - noktls - nopoll - noreuseport - nosplice - profiling.memory - profiling.tasks - server-state-base - server-state-file - spread-checks - ssl-engine - ssl-mode-async - tune.applet.zero-copy-forwarding - tune.buffers.limit - tune.buffers.reserve - tune.bufsize - tune.bufsize.large - tune.bufsize.small - tune.cli.max-payload-size - tune.comp.maxlevel - tune.defaults.purge - tune.disable-fast-forward - tune.disable-zero-copy-forwarding - tune.epoll.mask-events - tune.events.max-events-at-once - tune.fail-alloc - tune.fd.edge-triggered - tune.h1.be.glitches-threshold - tune.h1.fe.glitches-threshold - tune.h1.zero-copy-fwd-recv - tune.h1.zero-copy-fwd-send - tune.h2.be.glitches-threshold - tune.h2.be.initial-window-size - tune.h2.be.max-concurrent-streams - tune.h2.be.max-frames-at-once - tune.h2.be.rxbuf - tune.h2.fe.glitches-threshold - tune.h2.fe.initial-window-size - tune.h2.fe.max-concurrent-streams - tune.h2.fe.max-frames-at-once - tune.h2.fe.max-rst-at-once - tune.h2.fe.max-total-streams - tune.h2.fe.rxbuf - tune.h2.header-table-size - tune.h2.initial-window-size - tune.h2.max-concurrent-streams - tune.h2.max-frame-size - tune.h2.zero-copy-fwd-send - tune.http.cookielen - tune.http.logurilen - tune.http.maxhdr - tune.idle-pool.shared - tune.idletimer - tune.lua.bool-sample-conversion - tune.lua.burst-timeout - tune.lua.forced-yield - tune.lua.log.loggers - tune.lua.log.stderr - tune.lua.maxmem - tune.lua.openlibs - tune.lua.service-timeout - tune.lua.session-timeout - tune.lua.task-timeout - tune.max-checks-per-thread - tune.maxaccept - tune.maxpollevents - tune.maxrewrite - tune.max-rules-at-once - tune.memory.hot-size - tune.pattern.cache-size - tune.peers.max-updates-at-once - tune.pipesize - tune.pool-high-fd-ratio - tune.pool-low-fd-ratio - tune.pt.zero-copy-forwarding - tune.quic.be.cc.cubic-min-losses - tune.quic.be.cc.hystart - tune.quic.be.cc.max-frame-loss - tune.quic.be.cc.max-win-size - tune.quic.be.cc.reorder-ratio - tune.quic.be.max-idle-timeout - tune.quic.be.sec.glitches-threshold - tune.quic.be.stream.data-ratio - tune.quic.be.stream.max-concurrent - tune.quic.be.stream.rxbuf - tune.quic.be.tx.pacing - tune.quic.be.tx.udp-gso - tune.quic.cc.cubic.min-losses (deprecated) - tune.quic.cc-hystart (deprecated) - tune.quic.disable-tx-pacing (deprecated) - tune.quic.disable-udp-gso (deprecated) - tune.quic.fe.cc.cubic-min-losses - tune.quic.fe.cc.hystart - tune.quic.fe.cc.max-frame-loss - tune.quic.fe.cc.max-win-size - tune.quic.fe.cc.reorder-ratio - tune.quic.fe.max-idle-timeout - tune.quic.fe.sec.glitches-threshold - tune.quic.fe.sec.retry-threshold - tune.quic.fe.sock-per-conn - tune.quic.fe.stream.data-ratio - tune.quic.fe.stream.max-concurrent - tune.quic.fe.stream.max-total - tune.quic.fe.stream.rxbuf - tune.quic.fe.tx.pacing - tune.quic.fe.tx.udp-gso - tune.quic.frontend.max-data-size (deprecated) - tune.quic.frontend.max-idle-timeout (deprecated) - tune.quic.frontend.max-streams-bidi (deprecated) - tune.quic.frontend.max-tx-mem (deprecated) - tune.quic.frontend.stream-data-ratio (deprecated) - tune.quic.frontend.default-max-window-size (deprecated) - tune.quic.listen - tune.quic.max-frame-loss (deprecated) - tune.quic.mem.tx-max - tune.quic.reorder-ratio (deprecated) - tune.quic.retry-threshold (deprecated) - tune.quic.socket-owner (deprecated) - tune.quic.zero-copy-fwd-send - tune.renice.runtime - tune.renice.startup - tune.rcvbuf.backend - tune.rcvbuf.client - tune.rcvbuf.frontend - tune.rcvbuf.server - tune.recv_enough - tune.ring.queues - tune.runqueue-depth - tune.sched.low-latency - tune.sndbuf.backend - tune.sndbuf.client - tune.sndbuf.frontend - tune.sndbuf.server - tune.streams-elasticity - tune.stick-counters - tune.ssl.cachesize - tune.ssl.capture-buffer-size - tune.ssl.capture-cipherlist-size (deprecated) - tune.ssl.certificate-compression - tune.ssl.default-dh-param - tune.ssl.force-private-cache - tune.ssl.hard-maxrecord - tune.ssl.keylog - tune.ssl.keyupdate-rate-limit - tune.ssl.lifetime - tune.ssl.maxrecord - tune.ssl.ssl-ctx-cache-size - tune.ssl.ocsp-update.maxdelay (deprecated) - tune.ssl.ocsp-update.mindelay (deprecated) - tune.takeover-other-tg-connections - tune.vars.global-max-size - tune.vars.proc-max-size - tune.vars.reqres-max-size - tune.vars.sess-max-size - tune.vars.txn-max-size - tune.zlib.memlevel - tune.zlib.windowsize - Debugging - anonkey - debug.counters - force-cfg-parser-pause - quiet - warn-blocked-traffic-after - zero-warning - HTTPClient - httpclient.resolvers.disabled - httpclient.resolvers.id - httpclient.resolvers.prefer - httpclient.retries - httpclient.ssl.ca-file - httpclient.ssl.verify - httpclient.timeout.connect ## 3.1. Process management and security {#section-3-1} **`51degrees-data-file `** ```haproxy 51degrees-data-file ``` The path of the 51Degrees data file to provide device detection services. The file should be unzipped and accessible by HAProxy with relevant permissions. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES. **`51degrees-property-name-list [ ...]`** ```haproxy 51degrees-property-name-list [ ...] ``` A list of 51Degrees property names to be load from the dataset. A full list of names is available on the 51Degrees website: Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES. **`51degrees-property-separator `** ```haproxy 51degrees-property-separator ``` A char that will be appended to every property value in a response header containing 51Degrees results. If not set that will be set as ','. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES. **`51degrees-cache-size `** ```haproxy 51degrees-cache-size ``` Sets the size of the 51Degrees converter cache to `` entries. This is an LRU cache which reminds previous device detections and their results. By default, this cache is disabled. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES. **`51degrees-use-performance-graph { on | off }`** ```haproxy 51degrees-use-performance-graph { on | off } ``` Enables ('on') or disables ('off') the use of the performance graph in the detection process. The default value depends on 51Degrees library. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES and 51DEGREES_VER=4. **`51degrees-use-predictive-graph { on | off }`** ```haproxy 51degrees-use-predictive-graph { on | off } ``` Enables ('on') or disables ('off') the use of the predictive graph in the detection process. The default value depends on 51Degrees library. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES and 51DEGREES_VER=4. **`51degrees-drift `** ```haproxy 51degrees-drift ``` Sets the drift value that a detection can allow. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES and 51DEGREES_VER=4. **`51degrees-difference `** ```haproxy 51degrees-difference ``` Sets the difference value that a detection can allow. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES and 51DEGREES_VER=4. **`51degrees-allow-unmatched { on | off }`** ```haproxy 51degrees-allow-unmatched { on | off } ``` Enables ('on') or disables ('off') the use of unmatched nodes in the detection process. The default value depends on 51Degrees library. Please note that this option is only available when HAProxy has been compiled with USE_51DEGREES and 51DEGREES_VER=4. **`acme.scheduler { auto | off }`** ```haproxy acme.scheduler { auto | off } ``` Enable or disable the ACME scheduler. The ACME scheduler starts at HAProxy startup, it will loop over the certificates and start an ACME renewal task when the notAfter value is past curtime + (notAfter - notBefore) / 12, or 7 days if notBefore is not defined. The scheduler will then sleep and wakeup after 12 hours. The default value is "auto". See also: acme **`ca-base `** ```haproxy ca-base ``` Assigns a default directory to fetch SSL CA certificates and CRLs from when a relative path is used with "ca-file", "ca-verify-file" or "crl-file" directives. Absolute locations specified in "ca-file", "ca-verify-file" and "crl-file" prevail and ignore "ca-base". **`chroot { | auto }`** ```haproxy chroot { | auto } ``` Changes current directory to `` and performs a chroot() there before dropping privileges. This increases the security level in case an unknown vulnerability would be exploited, since it would make it very hard for the attacker to exploit the system. It is important to ensure that `` is both empty and non-writable to anyone. When the process is started with superuser privileges, the chroot() is performed directly. On Linux, when started unprivileged, haproxy attempts to perform it from inside a new user namespace created with unshare(CLONE_NEWUSER); if that mechanism is unavailable the chroot() will fail with the usual error. As a special case, `` may be set to "auto", in which case haproxy creates an anonymous temporary directory, unlinks it, and chroots into it. The resulting jail has no name in the filesystem and is empty and read-only, removing the need to prepare a dedicated jail directory. When starting with superuser privileges, a warning will be displayed if no chroot is used, in order to encourage users to always use the mechanism. If for any reason there is a compelling reason not to use chroot (e.g. access to a server via a UNIX socket with an unconvenient path), it remains possible to silence the warning by adding an explicit "chroot /", which has the benefit of being visible in a configuration. **`close-spread-time