--- title: "3. 全局段" linkTitle: "3. 全局段" weight: 140 description: "进程安全、性能调优、调试和 HTTP 客户端设置" icon: fa-solid fa-earth-americas module: [HAPROXY] categories: [参考] aliases: - /haproxy/configuration/global/ - /docs/haproxy/configuration/global/ - /haproxy/global/ upstream_link: "https://docs.haproxy.org/3.4/configuration.html" upstream_name: "HAProxy 3.4 Configuration Manual" upstream_ref: "v3.4.4, chapter 3" --- “global” 段中的参数为进程级配置,通常与操作系统相关。这些参数通常只需一次性设置,一旦配置正确便无需再修改。部分参数在命令行中也有对应选项。 以下关键字在 "global" 段中受支持: - 进程管理与安全 - 51degrees-allow-unmatched - 51degrees-cache-size - 51degrees-data-file - 51degrees-difference - 51degrees-drift - 51degrees-property-name-list - 51degrees-property-separator - 51degrees-use-performance-graph - 51degrees-use-predictive-graph - ca-base - chroot - cluster-secret - cpu-affinity - cpu-map - cpu-policy - cpu-set - crt-base - daemon - default-path - description - deviceatlas-json-file - deviceatlas-log-level - deviceatlas-properties-cookie - deviceatlas-separator - dns-accept-family - expose-deprecated-directives - expose-experimental-directives - external-check - fd-hard-limit - gid - grace - group - h1-accept-payload-with-any-method - h1-case-adjust - h1-case-adjust-file - h1-do-not-close-on-insecure-transfer-encoding - h2-workaround-bogus-websocket-clients - hard-stop-after - harden.reject-privileged-ports.tcp - harden.reject-privileged-ports.quic - insecure-fork-wanted - insecure-setuid-wanted - issuers-chain-path - jwt.decrypt_alg_list - jwt.decrypt_enc_list - key-base - limited-quic - localpeer - log - log-send-hostname - log-tag - lua-load - lua-load-per-thread - lua-prepend-path - max-threads-per-group - mworker-max-reloads - nbthread - node - numa-cpu-mapping - ocsp-update.disable - ocsp-update.maxdelay - ocsp-update.mindelay - ocsp-update.httpproxy - ocsp-update.mode - pidfile - pp2-never-send-local - presetenv - prealloc-fd - resetenv - set-dumpable - set-var - setenv - ssl-default-bind-ciphers - ssl-default-bind-ciphersuites - ssl-default-bind-client-sigalgs - ssl-default-bind-curves - ssl-default-bind-options - ssl-default-bind-sigalgs - ssl-default-server-ciphers - ssl-default-server-ciphersuites - ssl-default-server-client-sigalgs - ssl-default-server-curves - ssl-default-server-options - ssl-default-server-sigalgs - ssl-dh-param-file - ssl-propquery - ssl-provider - ssl-provider-path - ssl-security-level - ssl-server-verify - ssl-skip-self-issued-ca - stats - stats-file - strict-limits - uid - ulimit-n - unix-bind - unsetenv - user - wurfl-cache-size - wurfl-data-file - wurfl-information-list - wurfl-information-list-separator - 性能调优 - busy-polling - max-spread-checks - maxcompcpuusage - maxcomprate - maxconn - maxconnrate - maxpipes - maxsessrate - maxsslconn - maxsslrate - maxzlibmem - no-memory-trimming - noepoll - noevports - nogetaddrinfo - nokqueue - noktls - nopoll - noreuseport - nosplice - profiling.memory - profiling.tasks - server-state-base - server-state-file - spread-checks - ssl-engine - ssl-mode-async - tune.applet.zero-copy-forwarding - tune.buffers.limit - tune.buffers.reserve - tune.bufsize - tune.bufsize.large - tune.bufsize.small - tune.cli.max-payload-size - tune.comp.maxlevel - tune.defaults.purge - tune.disable-fast-forward - tune.disable-zero-copy-forwarding - tune.epoll.mask-events - tune.events.max-events-at-once - tune.fail-alloc - tune.fd.edge-triggered - tune.h1.be.glitches-threshold - tune.h1.fe.glitches-threshold - tune.h1.zero-copy-fwd-recv - tune.h1.zero-copy-fwd-send - tune.h2.be.glitches-threshold - tune.h2.be.initial-window-size - tune.h2.be.max-concurrent-streams - tune.h2.be.max-frames-at-once - tune.h2.be.rxbuf - tune.h2.fe.glitches-threshold - tune.h2.fe.initial-window-size - tune.h2.fe.max-concurrent-streams - tune.h2.fe.max-frames-at-once - tune.h2.fe.max-rst-at-once - tune.h2.fe.max-total-streams - tune.h2.fe.rxbuf - tune.h2.header-table-size - tune.h2.initial-window-size - tune.h2.max-concurrent-streams - tune.h2.max-frame-size - tune.h2.zero-copy-fwd-send - tune.http.cookielen - tune.http.logurilen - tune.http.maxhdr - tune.idle-pool.shared - tune.idletimer - tune.lua.bool-sample-conversion - tune.lua.burst-timeout - tune.lua.forced-yield - tune.lua.log.loggers - tune.lua.log.stderr - tune.lua.maxmem - tune.lua.openlibs - tune.lua.service-timeout - tune.lua.session-timeout - tune.lua.task-timeout - tune.max-checks-per-thread - tune.maxaccept - tune.maxpollevents - tune.maxrewrite - tune.max-rules-at-once - tune.memory.hot-size - tune.pattern.cache-size - tune.peers.max-updates-at-once - tune.pipesize - tune.pool-high-fd-ratio - tune.pool-low-fd-ratio - tune.pt.zero-copy-forwarding - tune.quic.be.cc.cubic-min-losses - tune.quic.be.cc.hystart - tune.quic.be.cc.max-frame-loss - tune.quic.be.cc.max-win-size - tune.quic.be.cc.reorder-ratio - tune.quic.be.max-idle-timeout - tune.quic.be.sec.glitches-threshold - tune.quic.be.stream.data-ratio - tune.quic.be.stream.max-concurrent - tune.quic.be.stream.rxbuf - tune.quic.be.tx.pacing - tune.quic.be.tx.udp-gso - tune.quic.cc.cubic.min-losses (已弃用) - tune.quic.cc-hystart (已弃用) - tune.quic.disable-tx-pacing (已弃用) - tune.quic.disable-udp-gso (已弃用) - tune.quic.fe.cc.cubic-min-losses - tune.quic.fe.cc.hystart - tune.quic.fe.cc.max-frame-loss - tune.quic.fe.cc.max-win-size - tune.quic.fe.cc.reorder-ratio - tune.quic.fe.max-idle-timeout - tune.quic.fe.sec.glitches-threshold - tune.quic.fe.sec.retry-threshold - tune.quic.fe.sock-per-conn - tune.quic.fe.stream.data-ratio - tune.quic.fe.stream.max-concurrent - tune.quic.fe.stream.max-total - tune.quic.fe.stream.rxbuf - tune.quic.fe.tx.pacing - tune.quic.fe.tx.udp-gso - tune.quic.frontend.max-data-size (已弃用) - tune.quic.frontend.max-idle-timeout (已弃用) - tune.quic.frontend.max-streams-bidi (已弃用) - tune.quic.frontend.max-tx-mem (已弃用) - tune.quic.frontend.stream-data-ratio (已弃用) - tune.quic.frontend.default-max-window-size (已弃用) - tune.quic.listen - tune.quic.max-frame-loss (已弃用) - tune.quic.mem.tx-max - tune.quic.reorder-ratio (已弃用) - tune.quic.retry-threshold (已弃用) - tune.quic.socket-owner (已弃用) - tune.quic.zero-copy-fwd-send - tune.renice.runtime - tune.renice.startup - tune.rcvbuf.backend - tune.rcvbuf.client - tune.rcvbuf.frontend - tune.rcvbuf.server - tune.recv_enough - tune.ring.queues - tune.runqueue-depth - tune.sched.low-latency - tune.sndbuf.backend - tune.sndbuf.client - tune.sndbuf.frontend - tune.sndbuf.server - tune.streams-elasticity - tune.stick-counters - tune.ssl.cachesize - tune.ssl.capture-buffer-size - tune.ssl.capture-cipherlist-size (已弃用) - tune.ssl.certificate-compression - tune.ssl.default-dh-param - tune.ssl.force-private-cache - tune.ssl.hard-maxrecord - tune.ssl.keylog - tune.ssl.keyupdate-rate-limit - tune.ssl.lifetime - tune.ssl.maxrecord - tune.ssl.ssl-ctx-cache-size - tune.ssl.ocsp-update.maxdelay (已弃用) - tune.ssl.ocsp-update.mindelay (已弃用) - tune.takeover-other-tg-connections - tune.vars.global-max-size - tune.vars.proc-max-size - tune.vars.reqres-max-size - tune.vars.sess-max-size - tune.vars.txn-max-size - tune.zlib.memlevel - tune.zlib.windowsize - 调试 - anonkey - debug.counters - force-cfg-parser-pause - quiet - warn-blocked-traffic-after - zero-warning - HTTPClient - httpclient.resolvers.disabled - httpclient.resolvers.id - httpclient.resolvers.prefer - httpclient.retries - httpclient.ssl.ca-file - httpclient.ssl.verify - httpclient.timeout.connect ## 3.1. 进程管理与安全 {#section-3-1} **`51degrees-data-file `** ```haproxy 51degrees-data-file ``` 用于提供设备检测服务的 51Degrees 数据文件路径。该文件应已解压,并可由 HAProxy 以相应权限访问。 请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。 **`51degrees-property-name-list [ ...]`** ```haproxy 51degrees-property-name-list [ ...] ``` 要从数据集加载的 51Degrees 属性名称列表。完整名称列表可在 51Degrees 官网获取: 请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。 **`51degrees-property-separator `** ```haproxy 51degrees-property-separator ``` 在包含 51Degrees 结果的响应头中,每个属性值后将追加一个字符。若未设置,则默认为“,”。 请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。 **`51degrees-cache-size `** ```haproxy 51degrees-cache-size ``` 设置 51Degrees 转换器缓存的大小为 `` 项。该缓存为 LRU 缓存,用于保留之前的设备检测及其结果。默认情况下,此缓存处于禁用状态。 请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。 **`51degrees-use-performance-graph { on | off }`** ```haproxy 51degrees-use-performance-graph { on | off } ``` 启用('on')或禁用('off')检测过程中对性能图的使用。默认值取决于 51Degrees 库。 请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。 **`51degrees-use-predictive-graph { on | off }`** ```haproxy 51degrees-use-predictive-graph { on | off } ``` 启用('on')或禁用('off')检测过程中对预测图的使用。默认值取决于 51Degrees 库。 请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。 **`51degrees-drift `** ```haproxy 51degrees-drift ``` 设置检测允许的漂移值。 请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。 **`51degrees-difference `** ```haproxy 51degrees-difference ``` 设置检测可允许的差异值。 请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。 **`51degrees-allow-unmatched { on | off }`** ```haproxy 51degrees-allow-unmatched { on | off } ``` 启用('on')或禁用('off')检测过程中使用未匹配节点。默认值取决于 51Degrees 库。 请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。 **`acme.scheduler { auto | off }`** ```haproxy acme.scheduler { auto | off } ``` 启用或禁用 ACME 调度器。 ACME 调度器在 HAProxy 启动时开始运行,它将遍历所有证书,并在 notAfter 值超过当前时间加上 (notAfter - notBefore) / 12 时启动 ACME 证书续订任务;若 notBefore 未定义,则使用 7 天作为阈值。调度器随后将休眠,并在 12 小时后唤醒。 默认值为 "auto"。 另请参阅:acme **`ca-base `** ```haproxy ca-base ``` 为当使用相对路径时,指定从何处获取 SSL CA 证书和 CRL 的默认目录,该目录适用于 "ca-file"、"ca-verify-file" 或 "crl-file" 指令。在 "ca-file"、"ca-verify-file" 和 "crl-file" 中指定的绝对路径具有优先权,并忽略 "ca-base"。 **`chroot { | auto }`** ```haproxy chroot { | auto } ``` 将当前目录切换至 ``,并在降权前在此处执行 chroot() 操作。 若存在未知漏洞被利用,此操作可显著提升安全性,使攻击者难以进一步利用系统。 必须确保 `` 对任何用户均为空且不可写。 当以超级用户权限启动进程时,将直接执行 chroot()。 在 Linux 系统上,若以非特权身份启动,HAProxy 会尝试通过 unshare(CLONE_NEWUSER) 创建的新用户命名空间内执行 chroot();若该机制不可用,chroot() 将以常规错误失败。 作为特殊情况,`` 可设置为 "auto",此时 HAProxy 会创建一个匿名临时目录,将其删除,并 chroot 进入该目录。resulting jail 在文件系统中无名称,且为空且只读,从而无需预先准备专用的 jail 目录。 以超级用户权限启动时,若未使用 chroot,将显示警告信息,以鼓励用户始终使用该机制。若因特定原因必须不使用 chroot(例如通过路径不便的 Unix 套接字访问服务器),仍可通过显式添加 "chroot /" 来静默警告,此举的优点在于配置中可见。 **`close-spread-time