---
title: "3. 全局段"
linkTitle: "3. 全局段"
weight: 140
description: "进程安全、性能调优、调试和 HTTP 客户端设置"
icon: fa-solid fa-earth-americas
module: [HAPROXY]
categories: [参考]
aliases:
- /haproxy/configuration/global/
- /docs/haproxy/configuration/global/
- /haproxy/global/
upstream_link: "https://docs.haproxy.org/3.4/configuration.html"
upstream_name: "HAProxy 3.4 Configuration Manual"
upstream_ref: "v3.4.4, chapter 3"
---
“global” 段中的参数为进程级配置,通常与操作系统相关。这些参数通常只需一次性设置,一旦配置正确便无需再修改。部分参数在命令行中也有对应选项。
以下关键字在 "global" 段中受支持:
- 进程管理与安全
- 51degrees-allow-unmatched
- 51degrees-cache-size
- 51degrees-data-file
- 51degrees-difference
- 51degrees-drift
- 51degrees-property-name-list
- 51degrees-property-separator
- 51degrees-use-performance-graph
- 51degrees-use-predictive-graph
- ca-base
- chroot
- cluster-secret
- cpu-affinity
- cpu-map
- cpu-policy
- cpu-set
- crt-base
- daemon
- default-path
- description
- deviceatlas-json-file
- deviceatlas-log-level
- deviceatlas-properties-cookie
- deviceatlas-separator
- dns-accept-family
- expose-deprecated-directives
- expose-experimental-directives
- external-check
- fd-hard-limit
- gid
- grace
- group
- h1-accept-payload-with-any-method
- h1-case-adjust
- h1-case-adjust-file
- h1-do-not-close-on-insecure-transfer-encoding
- h2-workaround-bogus-websocket-clients
- hard-stop-after
- harden.reject-privileged-ports.tcp
- harden.reject-privileged-ports.quic
- insecure-fork-wanted
- insecure-setuid-wanted
- issuers-chain-path
- jwt.decrypt_alg_list
- jwt.decrypt_enc_list
- key-base
- limited-quic
- localpeer
- log
- log-send-hostname
- log-tag
- lua-load
- lua-load-per-thread
- lua-prepend-path
- max-threads-per-group
- mworker-max-reloads
- nbthread
- node
- numa-cpu-mapping
- ocsp-update.disable
- ocsp-update.maxdelay
- ocsp-update.mindelay
- ocsp-update.httpproxy
- ocsp-update.mode
- pidfile
- pp2-never-send-local
- presetenv
- prealloc-fd
- resetenv
- set-dumpable
- set-var
- setenv
- ssl-default-bind-ciphers
- ssl-default-bind-ciphersuites
- ssl-default-bind-client-sigalgs
- ssl-default-bind-curves
- ssl-default-bind-options
- ssl-default-bind-sigalgs
- ssl-default-server-ciphers
- ssl-default-server-ciphersuites
- ssl-default-server-client-sigalgs
- ssl-default-server-curves
- ssl-default-server-options
- ssl-default-server-sigalgs
- ssl-dh-param-file
- ssl-propquery
- ssl-provider
- ssl-provider-path
- ssl-security-level
- ssl-server-verify
- ssl-skip-self-issued-ca
- stats
- stats-file
- strict-limits
- uid
- ulimit-n
- unix-bind
- unsetenv
- user
- wurfl-cache-size
- wurfl-data-file
- wurfl-information-list
- wurfl-information-list-separator
- 性能调优
- busy-polling
- max-spread-checks
- maxcompcpuusage
- maxcomprate
- maxconn
- maxconnrate
- maxpipes
- maxsessrate
- maxsslconn
- maxsslrate
- maxzlibmem
- no-memory-trimming
- noepoll
- noevports
- nogetaddrinfo
- nokqueue
- noktls
- nopoll
- noreuseport
- nosplice
- profiling.memory
- profiling.tasks
- server-state-base
- server-state-file
- spread-checks
- ssl-engine
- ssl-mode-async
- tune.applet.zero-copy-forwarding
- tune.buffers.limit
- tune.buffers.reserve
- tune.bufsize
- tune.bufsize.large
- tune.bufsize.small
- tune.cli.max-payload-size
- tune.comp.maxlevel
- tune.defaults.purge
- tune.disable-fast-forward
- tune.disable-zero-copy-forwarding
- tune.epoll.mask-events
- tune.events.max-events-at-once
- tune.fail-alloc
- tune.fd.edge-triggered
- tune.h1.be.glitches-threshold
- tune.h1.fe.glitches-threshold
- tune.h1.zero-copy-fwd-recv
- tune.h1.zero-copy-fwd-send
- tune.h2.be.glitches-threshold
- tune.h2.be.initial-window-size
- tune.h2.be.max-concurrent-streams
- tune.h2.be.max-frames-at-once
- tune.h2.be.rxbuf
- tune.h2.fe.glitches-threshold
- tune.h2.fe.initial-window-size
- tune.h2.fe.max-concurrent-streams
- tune.h2.fe.max-frames-at-once
- tune.h2.fe.max-rst-at-once
- tune.h2.fe.max-total-streams
- tune.h2.fe.rxbuf
- tune.h2.header-table-size
- tune.h2.initial-window-size
- tune.h2.max-concurrent-streams
- tune.h2.max-frame-size
- tune.h2.zero-copy-fwd-send
- tune.http.cookielen
- tune.http.logurilen
- tune.http.maxhdr
- tune.idle-pool.shared
- tune.idletimer
- tune.lua.bool-sample-conversion
- tune.lua.burst-timeout
- tune.lua.forced-yield
- tune.lua.log.loggers
- tune.lua.log.stderr
- tune.lua.maxmem
- tune.lua.openlibs
- tune.lua.service-timeout
- tune.lua.session-timeout
- tune.lua.task-timeout
- tune.max-checks-per-thread
- tune.maxaccept
- tune.maxpollevents
- tune.maxrewrite
- tune.max-rules-at-once
- tune.memory.hot-size
- tune.pattern.cache-size
- tune.peers.max-updates-at-once
- tune.pipesize
- tune.pool-high-fd-ratio
- tune.pool-low-fd-ratio
- tune.pt.zero-copy-forwarding
- tune.quic.be.cc.cubic-min-losses
- tune.quic.be.cc.hystart
- tune.quic.be.cc.max-frame-loss
- tune.quic.be.cc.max-win-size
- tune.quic.be.cc.reorder-ratio
- tune.quic.be.max-idle-timeout
- tune.quic.be.sec.glitches-threshold
- tune.quic.be.stream.data-ratio
- tune.quic.be.stream.max-concurrent
- tune.quic.be.stream.rxbuf
- tune.quic.be.tx.pacing
- tune.quic.be.tx.udp-gso
- tune.quic.cc.cubic.min-losses (已弃用)
- tune.quic.cc-hystart (已弃用)
- tune.quic.disable-tx-pacing (已弃用)
- tune.quic.disable-udp-gso (已弃用)
- tune.quic.fe.cc.cubic-min-losses
- tune.quic.fe.cc.hystart
- tune.quic.fe.cc.max-frame-loss
- tune.quic.fe.cc.max-win-size
- tune.quic.fe.cc.reorder-ratio
- tune.quic.fe.max-idle-timeout
- tune.quic.fe.sec.glitches-threshold
- tune.quic.fe.sec.retry-threshold
- tune.quic.fe.sock-per-conn
- tune.quic.fe.stream.data-ratio
- tune.quic.fe.stream.max-concurrent
- tune.quic.fe.stream.max-total
- tune.quic.fe.stream.rxbuf
- tune.quic.fe.tx.pacing
- tune.quic.fe.tx.udp-gso
- tune.quic.frontend.max-data-size (已弃用)
- tune.quic.frontend.max-idle-timeout (已弃用)
- tune.quic.frontend.max-streams-bidi (已弃用)
- tune.quic.frontend.max-tx-mem (已弃用)
- tune.quic.frontend.stream-data-ratio (已弃用)
- tune.quic.frontend.default-max-window-size (已弃用)
- tune.quic.listen
- tune.quic.max-frame-loss (已弃用)
- tune.quic.mem.tx-max
- tune.quic.reorder-ratio (已弃用)
- tune.quic.retry-threshold (已弃用)
- tune.quic.socket-owner (已弃用)
- tune.quic.zero-copy-fwd-send
- tune.renice.runtime
- tune.renice.startup
- tune.rcvbuf.backend
- tune.rcvbuf.client
- tune.rcvbuf.frontend
- tune.rcvbuf.server
- tune.recv_enough
- tune.ring.queues
- tune.runqueue-depth
- tune.sched.low-latency
- tune.sndbuf.backend
- tune.sndbuf.client
- tune.sndbuf.frontend
- tune.sndbuf.server
- tune.streams-elasticity
- tune.stick-counters
- tune.ssl.cachesize
- tune.ssl.capture-buffer-size
- tune.ssl.capture-cipherlist-size (已弃用)
- tune.ssl.certificate-compression
- tune.ssl.default-dh-param
- tune.ssl.force-private-cache
- tune.ssl.hard-maxrecord
- tune.ssl.keylog
- tune.ssl.keyupdate-rate-limit
- tune.ssl.lifetime
- tune.ssl.maxrecord
- tune.ssl.ssl-ctx-cache-size
- tune.ssl.ocsp-update.maxdelay (已弃用)
- tune.ssl.ocsp-update.mindelay (已弃用)
- tune.takeover-other-tg-connections
- tune.vars.global-max-size
- tune.vars.proc-max-size
- tune.vars.reqres-max-size
- tune.vars.sess-max-size
- tune.vars.txn-max-size
- tune.zlib.memlevel
- tune.zlib.windowsize
- 调试
- anonkey
- debug.counters
- force-cfg-parser-pause
- quiet
- warn-blocked-traffic-after
- zero-warning
- HTTPClient
- httpclient.resolvers.disabled
- httpclient.resolvers.id
- httpclient.resolvers.prefer
- httpclient.retries
- httpclient.ssl.ca-file
- httpclient.ssl.verify
- httpclient.timeout.connect
## 3.1. 进程管理与安全 {#section-3-1}
**`51degrees-data-file `**
```haproxy
51degrees-data-file
```
用于提供设备检测服务的 51Degrees 数据文件路径。该文件应已解压,并可由 HAProxy 以相应权限访问。
请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。
**`51degrees-property-name-list [ ...]`**
```haproxy
51degrees-property-name-list [ ...]
```
要从数据集加载的 51Degrees 属性名称列表。完整名称列表可在 51Degrees 官网获取:
请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。
**`51degrees-property-separator `**
```haproxy
51degrees-property-separator
```
在包含 51Degrees 结果的响应头中,每个属性值后将追加一个字符。若未设置,则默认为“,”。
请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。
**`51degrees-cache-size `**
```haproxy
51degrees-cache-size
```
设置 51Degrees 转换器缓存的大小为 `` 项。该缓存为 LRU 缓存,用于保留之前的设备检测及其结果。默认情况下,此缓存处于禁用状态。
请注意,此选项仅在 HAProxy 编译时包含 USE_51DEGREES 时可用。
**`51degrees-use-performance-graph { on | off }`**
```haproxy
51degrees-use-performance-graph { on | off }
```
启用('on')或禁用('off')检测过程中对性能图的使用。默认值取决于 51Degrees 库。
请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。
**`51degrees-use-predictive-graph { on | off }`**
```haproxy
51degrees-use-predictive-graph { on | off }
```
启用('on')或禁用('off')检测过程中对预测图的使用。默认值取决于 51Degrees 库。
请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。
**`51degrees-drift `**
```haproxy
51degrees-drift
```
设置检测允许的漂移值。
请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。
**`51degrees-difference `**
```haproxy
51degrees-difference
```
设置检测可允许的差异值。
请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。
**`51degrees-allow-unmatched { on | off }`**
```haproxy
51degrees-allow-unmatched { on | off }
```
启用('on')或禁用('off')检测过程中使用未匹配节点。默认值取决于 51Degrees 库。
请注意,此选项仅在 HAProxy 使用 USE_51DEGREES 和 51DEGREES_VER=4 编译时可用。
**`acme.scheduler { auto | off }`**
```haproxy
acme.scheduler { auto | off }
```
启用或禁用 ACME 调度器。
ACME 调度器在 HAProxy 启动时开始运行,它将遍历所有证书,并在 notAfter 值超过当前时间加上 (notAfter - notBefore) / 12 时启动 ACME 证书续订任务;若 notBefore 未定义,则使用 7 天作为阈值。调度器随后将休眠,并在 12 小时后唤醒。
默认值为 "auto"。
另请参阅:acme
**`ca-base `**
```haproxy
ca-base
```
为当使用相对路径时,指定从何处获取 SSL CA 证书和 CRL 的默认目录,该目录适用于 "ca-file"、"ca-verify-file" 或 "crl-file" 指令。在 "ca-file"、"ca-verify-file" 和 "crl-file" 中指定的绝对路径具有优先权,并忽略 "ca-base"。
**`chroot { | auto }`**
```haproxy
chroot { | auto }
```
将当前目录切换至 ``,并在降权前在此处执行 chroot() 操作。
若存在未知漏洞被利用,此操作可显著提升安全性,使攻击者难以进一步利用系统。
必须确保 `` 对任何用户均为空且不可写。
当以超级用户权限启动进程时,将直接执行 chroot()。
在 Linux 系统上,若以非特权身份启动,HAProxy 会尝试通过 unshare(CLONE_NEWUSER) 创建的新用户命名空间内执行 chroot();若该机制不可用,chroot() 将以常规错误失败。
作为特殊情况,`` 可设置为 "auto",此时 HAProxy 会创建一个匿名临时目录,将其删除,并 chroot 进入该目录。resulting jail 在文件系统中无名称,且为空且只读,从而无需预先准备专用的 jail 目录。
以超级用户权限启动时,若未使用 chroot,将显示警告信息,以鼓励用户始终使用该机制。若因特定原因必须不使用 chroot(例如通过路径不便的 Unix 套接字访问服务器),仍可通过显式添加 "chroot /" 来静默警告,此举的优点在于配置中可见。
**`close-spread-time