---
title: "9. 统计信息与监控"
linkTitle: "9. 统计信息与监控"
weight: 330
description: "CSV 和类型化统计信息、运行时 CLI 命令、主 CLI 和统计文件"
icon: fa-solid fa-chart-line
module: [HAPROXY]
categories: [任务]
aliases:
- /haproxy/management/statistics-and-monitoring/
- /docs/haproxy/management/statistics-and-monitoring/
- /haproxy/statistics-and-monitoring/
upstream_link: "https://docs.haproxy.org/3.4/management.html"
upstream_name: "HAProxy 3.4 Management Guide"
upstream_ref: "v3.4.4, chapter 9"
---
可以查询 HAProxy 的运行状态。最常用的机制是 HTTP 统计信息页面。该页面还提供了一种用于监控工具的替代 CSV 输出格式。相同的格式也通过 Unix 套接字提供。
统计信息按类别分组,类别以域(domain)命名,对应 HAProxy 的多个组件。当前提供两个域:proxy 和 resolvers。若未指定,将选择 proxy 域。请注意,仅代理的统计信息会显示在 HTTP 页面上。
## 9.1. CSV 格式 {#section-9-1}
可通过 Unix 套接字或 HTTP 页面查阅统计信息。两种方式均提供 CSV 格式,其字段定义如下。第一行以井号('#')开头,每个逗号分隔的字段对应一列标题。从第二行开始的其余行采用标准 CSV 格式,以逗号作为分隔符,双引号('"')作为可选的文本分隔符,仅当被包围的文本存在歧义时(如包含引号或逗号)才使用。文本中的双引号字符需以两个双引号('""')表示,这是大多数工具所识别的格式。请勿在这些字段前插入任何列,以免破坏依赖硬编码列位置的工具。
对于代理的统计信息,每个字段名后方括号内会列出该字段可能具有值的类型。类型包括 L(监听器)、F(前端)、B(后端)和 S(服务器)。存在一组固定的静态字段,其始终以相同顺序可用。包含字符“-”的列表示静态字段的结束,此后字段的存在性或顺序无法保证。
以下是使用代理统计信息域的静态字段列表:
```text
0. pxname [LFBS]: proxy name
1. svname [LFBS]: service name (FRONTEND for frontend, BACKEND for backend,
any name for server/listener)
2. qcur [..BS]: current queued requests. For the backend this reports the
number queued without a server assigned.
3. qmax [..BS]: max value of qcur
4. scur [LFBS]: current sessions
5. smax [LFBS]: max sessions
6. slim [LFBS]: configured session limit
7. stot [LFBS]: cumulative number of sessions
8. bin [LFBS]: bytes in
9. bout [LFBS]: bytes out
10. dreq [LFB.]: requests denied because of security concerns.
- For tcp this is because of a matched tcp-request content rule.
- For http this is because of a matched http-request or tarpit rule.
11. dresp [LFBS]: responses denied because of security concerns.
- For http this is because of a matched http-request rule, or
"option checkcache".
12. ereq [LF..]: request errors. Some of the possible causes are:
- early termination from the client, before the request has been sent.
- read error from the client
- client timeout
- client closed connection
- various bad requests from the client.
- request was tarpitted.
13. econ [..BS]: number of requests that encountered an error trying to
connect to a backend server. The backend stat is the sum of the stat
for all servers of that backend, plus any connection errors not
associated with a particular server (such as the backend having no
active servers).
14. eresp [..BS]: response errors. srv_abrt will be counted here also.
Some other errors are:
- write error on the client socket (won't be counted for the server stat)
- failure applying filters to the response.
15. wretr [..BS]: number of times a connection to a server was retried.
16. wredis [..BS]: number of times a request was redispatched to another
server. The server value counts the number of times that server was
switched away from.
17. status [LFBS]: status (UP/DOWN/NOLB/MAINT/MAINT(via)/MAINT(resolution)...)
18. weight [..BS]: total effective weight (backend), effective weight (server)
19. act [..BS]: number of active servers (backend), server is active (server)
20. bck [..BS]: number of backup servers (backend), server is backup (server)
21. chkfail [...S]: number of failed checks. (Only counts checks failed when
the server is up.)
22. chkdown [..BS]: number of UP->DOWN transitions. The backend counter counts
transitions to the whole backend being down, rather than the sum of the
counters for each server.
23. lastchg [..BS]: number of seconds since the last UP<->DOWN transition
24. downtime [..BS]: total downtime (in seconds). The value for the backend
is the downtime for the whole backend, not the sum of the server downtime.
25. qlimit [...S]: configured maxqueue for the server, or nothing in the
value is 0 (default, meaning no limit)
26. pid [LFBS]: process id (0 for first instance, 1 for second, ...)
27. iid [LFBS]: unique proxy id
28. sid [L..S]: server id (unique inside a proxy)
29. throttle [...S]: current throttle percentage for the server, when
slowstart is active, or no value if not in slowstart.
30. lbtot [..BS]: total number of times a server was selected, either for new
sessions, or when re-dispatching. The server counter is the number
of times that server was selected.
31. tracked [...S]: id of proxy/server if tracking is enabled.
32. type [LFBS]: (0=frontend, 1=backend, 2=server, 3=socket/listener)
33. rate [.FBS]: number of sessions per second over last elapsed second
34. rate_lim [.F..]: configured limit on new sessions per second
35. rate_max [.FBS]: max number of new sessions per second
36. check_status [...S]: status of last health check, one of:
UNK -> unknown
INI -> initializing
SOCKERR -> socket error
L4OK -> check passed on layer 4, no upper layers testing enabled
L4TOUT -> layer 1-4 timeout
L4CON -> layer 1-4 connection problem, for example
"Connection refused" (tcp rst) or "No route to host" (icmp)
L6OK -> check passed on layer 6
L6TOUT -> layer 6 (SSL) timeout
L6RSP -> layer 6 invalid response - protocol error
L7OK -> check passed on layer 7
L7OKC -> check conditionally passed on layer 7, for example 404 with
disable-on-404
L7TOUT -> layer 7 (HTTP/SMTP) timeout
L7RSP -> layer 7 invalid response - protocol error
L7STS -> layer 7 response error, for example HTTP 5xx
Notice: If a check is currently running, the last known status will be
reported, prefixed with "* ". e. g. "* L7OK".
37. check_code [...S]: layer5-7 code, if available
38. check_duration [...S]: time in ms took to finish last health check
39. hrsp_1xx [.FBS]: http responses with 1xx code
40. hrsp_2xx [.FBS]: http responses with 2xx code
41. hrsp_3xx [.FBS]: http responses with 3xx code
42. hrsp_4xx [.FBS]: http responses with 4xx code
43. hrsp_5xx [.FBS]: http responses with 5xx code
44. hrsp_other [.FBS]: http responses with other codes (protocol error)
45. hanafail [...S]: failed health checks details
46. req_rate [.F..]: HTTP requests per second over last elapsed second
47. req_rate_max [.F..]: max number of HTTP requests per second observed
48. req_tot [.FB.]: total number of HTTP requests received
49. cli_abrt [..BS]: number of data transfers aborted by the client
50. srv_abrt [..BS]: number of data transfers aborted by the server
(inc. in eresp)
51. comp_in [.FB.]: number of HTTP response bytes fed to the compressor
52. comp_out [.FB.]: number of HTTP response bytes emitted by the compressor
53. comp_byp [.FB.]: number of bytes that bypassed the HTTP compressor
(CPU/BW limit)
54. comp_rsp [.FB.]: number of HTTP responses that were compressed
55. lastsess [..BS]: number of seconds since last session assigned to
server/backend
56. last_chk [...S]: last health check contents or textual error
57. last_agt [...S]: last agent check contents or textual error
58. qtime [..BS]: the average queue time in ms over the 1024 last requests
59. ctime [..BS]: the average connect time in ms over the 1024 last requests
60. rtime [..BS]: the average response time in ms over the 1024 last requests
(0 for TCP)
61. ttime [..BS]: the average total session time in ms over the 1024 last
requests
62. agent_status [...S]: status of last agent check, one of:
UNK -> unknown
INI -> initializing
SOCKERR -> socket error
L4OK -> check passed on layer 4, no upper layers testing enabled
L4TOUT -> layer 1-4 timeout
L4CON -> layer 1-4 connection problem, for example
"Connection refused" (tcp rst) or "No route to host" (icmp)
L7OK -> agent reported "up"
L7STS -> agent reported "fail", "stop", or "down"
63. agent_code [...S]: numeric code reported by agent if any (unused for now)
64. agent_duration [...S]: time in ms taken to finish last check
65. check_desc [...S]: short human-readable description of check_status
66. agent_desc [...S]: short human-readable description of agent_status
67. check_rise [...S]: server's "rise" parameter used by checks
68. check_fall [...S]: server's "fall" parameter used by checks
69. check_health [...S]: server's health check value between 0 and rise+fall-1
70. agent_rise [...S]: agent's "rise" parameter, normally 1
71. agent_fall [...S]: agent's "fall" parameter, normally 1
72. agent_health [...S]: agent's health parameter, between 0 and rise+fall-1
73. addr [L..S]: address:port or "unix". IPv6 has brackets around the address.
74: cookie [..BS]: server's cookie value or backend's cookie name
75: mode [LFBS]: proxy mode (tcp, http, health, unknown)
76: algo [..B.]: load balancing algorithm
77: conn_rate [.F..]: number of connections over the last elapsed second
78: conn_rate_max [.F..]: highest known conn_rate
79: conn_tot [.F..]: cumulative number of connections
80: intercepted [.FB.]: cum. number of intercepted requests (monitor, stats)
81: dcon [LF..]: requests denied by "tcp-request connection" rules
82: dses [LF..]: requests denied by "tcp-request session" rules
83: wrew [LFBS]: cumulative number of failed header rewriting warnings
84: connect [..BS]: cumulative number of connection establishment attempts
85: reuse [..BS]: cumulative number of connection reuses
86: cache_lookups [.FB.]: cumulative number of cache lookups
87: cache_hits [.FB.]: cumulative number of cache hits
88: srv_icur [...S]: current number of idle connections available for reuse
89: src_ilim [...S]: limit on the number of available idle connections
90. qtime_max [..BS]: the maximum observed queue time in ms
91. ctime_max [..BS]: the maximum observed connect time in ms
92. rtime_max [..BS]: the maximum observed response time in ms (0 for TCP)
93. ttime_max [..BS]: the maximum observed total session time in ms
94. eint [LFBS]: cumulative number of internal errors
95. idle_conn_cur [...S]: current number of unsafe idle connections
96. safe_conn_cur [...S]: current number of safe idle connections
97. used_conn_cur [...S]: current number of connections in use
98. need_conn_est [...S]: estimated needed number of connections
99. uweight [..BS]: total user weight (backend), server user weight (server)
100. agg_server_status [..B.]: backend aggregated gauge of server's status
101. agg_server_status_check [..B.]: (deprecated)
102. agg_check_status [..B.]: backend aggregated gauge of server's state check
status
103. srid [...S]: server id revision
104. sess_other [.F..]: total number of sessions other than HTTP since process
started
105. h1_sess [.F..]: total number of HTTP/1 sessions since process started
106. h2_sess [.F..]: total number of HTTP/2 sessions since process started
107. h3_sess [.F..]: total number of HTTP/3 sessions since process started
108. req_other [.F..]: total number of sessions other than HTTP processed by
this object since the worker process started
109. h1req [.F..]: total number of HTTP/1 sessions processed by this object
since the worker process started
110. h2req [.F..]: total number of hTTP/2 sessions processed by this object
since the worker process started
111. h3req [.F..]: total number of HTTP/3 sessions processed by this object
since the worker process started
112. proto [L...]: protocol
113. priv_idle_cur [...S]: current number of private idle connections
114. reqbin [LFBS]: total number of request bytes received since the worker
process started
115. reqbout [LFBS]: total number of request bytes sent since the worker
process started
116. resbin [LFBS]: total number of response bytes received since the worker
process started
117. resbout [LFBS]: total number of response bytes sent since the worker
process started
```
对于所有其他统计信息域,字段的存在与否或顺序均无法保证。此时,应始终使用头行来解析 CSV 数据。
## 9.2. 类型化输出格式 {#section-9-2}
“show info” 和 “show stat” 均支持一种模式,其中每个输出值均附带其类型,以及足够信息以明确该值在进程间应如何聚合,以及其如何演变。
在所有情况下,输出格式为每行仅包含一个值,所有信息均以冒号(':')分隔的字段形式呈现。
第一列指定被转储的对象或指标。其格式由生成此输出的命令决定,本节不作说明。通常由一系列标识符和字段名组成。
第二列包含四个字符,分别表示所报告值的来源、性质、作用域和持久性状态。第一个字符(来源)表示该值的提取位置。可能的字符如下:
```text
M The value is a metric. It is valid at one instant any may change depending
on its nature .
S The value is a status. It represents a discrete value which by definition
cannot be aggregated. It may be the status of a server ("UP" or "DOWN"),
the PID of the process, etc.
K The value is a sorting key. It represents an identifier which may be used
to group some values together because it is unique among its class. All
internal identifiers are keys. Some names can be listed as keys if they
are unique (eg: a frontend name is unique). In general keys come from the
configuration, even though some of them may automatically be assigned. For
most purposes keys may be considered as equivalent to configuration.
C The value comes from the configuration. Certain configuration values make
sense on the output, for example a concurrent connection limit or a cookie
name. By definition these values are the same in all processes started
from the same configuration file.
P The value comes from the product itself. There are very few such values,
most common use is to report the product name, version and release date.
These elements are also the same between all processes.
```
第二个字符(即类型)用于表示字段所携带信息的性质,以便聚合器决定对多个值进行聚合时应采用的操作。可能的字符包括:
```text
A The value represents an age since a last event. This is a bit different
from the duration in that an age is automatically computed based on the
current date. A typical example is how long ago did the last session
happen on a server. Ages are generally aggregated by taking the minimum
value and do not need to be stored.
a The value represents an already averaged value. The average response times
and server weights are of this nature. Averages can typically be averaged
between processes.
C The value represents a cumulative counter. Such measures perpetually
increase until they wrap around. Some monitoring protocols need to tell
the difference between a counter and a gauge to report a different type.
In general counters may simply be summed since they represent events or
volumes. Examples of metrics of this nature are connection counts or byte
counts.
D The value represents a duration for a status. There are a few usages of
this, most of them include the time taken by the last health check and
the time a server has spent down. Durations are generally not summed,
most of the time the maximum will be retained to compute an SLA.
G The value represents a gauge. It's a measure at one instant. The memory
usage or the current number of active connections are of this nature.
Metrics of this type are typically summed during aggregation.
L The value represents a limit (generally a configured one). By nature,
limits are harder to aggregate since they are specific to the point where
they were retrieved. In certain situations they may be summed or be kept
separate.
M The value represents a maximum. In general it will apply to a gauge and
keep the highest known value. An example of such a metric could be the
maximum amount of concurrent connections that was encountered in the
product's life time. To correctly aggregate maxima, you are supposed to
output a range going from the maximum of all maxima and the sum of all
of them. There is indeed no way to know if they were encountered
simultaneously or not.
m The value represents a minimum. In general it will apply to a gauge and
keep the lowest known value. An example of such a metric could be the
minimum amount of free memory pools that was encountered in the product's
life time. To correctly aggregate minima, you are supposed to output a
range going from the minimum of all minima and the sum of all of them.
There is indeed no way to know if they were encountered simultaneously
or not.
N The value represents a name, so it is a string. It is used to report
proxy names, server names and cookie names. Names have configuration or
keys as their origin and are supposed to be the same among all processes.
O The value represents a free text output. Outputs from various commands,
returns from health checks, node descriptions are of such nature.
R The value represents an event rate. It's a measure at one instant. It is
quite similar to a gauge except that the recipient knows that this measure
moves slowly and may decide not to keep all values. An example of such a
metric is the measured amount of connections per second. Metrics of this
type are typically summed during aggregation.
T The value represents a date or time. A field emitting the current date
would be of this type. The method to aggregate such information is left
as an implementation choice. For now no field uses this type.
```
第三个字符(作用域)表示该值所反映的范围。某些元素可能与进程相关,而其他元素可能与配置或系统相关。明确这一区别至关重要,以判断在聚合过程中是否应保留单一值,还是必须对多个值进行聚合。当前支持的字符如下:
```text
C The value is valid for a whole cluster of nodes, which is the set of nodes
communicating over the peers protocol. An example could be the amount of
entries present in a stick table that is replicated with other peers. At
the moment no metric use this scope.
P The value is valid only for the process reporting it. Most metrics use
this scope.
S The value is valid for the whole service, which is the set of processes
started together from the same configuration file. All metrics originating
from the configuration use this scope. Some other metrics may use it as
well for some shared resources (eg: shared SSL cache statistics).
s The value is valid for the whole system, such as the system's hostname,
current date or resource usage. At the moment this scope is not used by
any metric.
```
第四个字符(持久性状态)表示该值(指标)在重载后是否保持持久。后续字符的含义如下:
```text
V The metric is volatile because it is local to the current process so
the value will be lost when reloading.
P The metric is persistent because it may be shared with other co-processes
so that the value is preserved across reloads.
```
消费这些信息的用户通常只需具备这 4 个字符即可准确报告跨多个进程的聚合信息。
在该列之后,第三列指示字段类型,包括 "s32"(有符号 32 位整数)、"s64"(有符号 64 位整数)、"u32"(无符号 32 位整数)、"u64"(无符号 64 位整数)和 "str"(字符串)。在解析值之前,必须了解其类型,以确保正确读取。例如,仅包含数字的字符串仍然是字符串,而非整数(如通过检查获取的错误码)。
第四列是值本身,其编码方式根据类型而定。字符串在冒号后直接输出,不加任何前导空格。若字符串中包含冒号,将正常显示。这意味着输出不应仅通过冒号进行分割,否则某些检查输出或服务器地址可能被截断。
## 9.3. Unix 套接字命令 {#section-9-3}
统计信息套接字默认未启用。如需启用,必须在 HAProxy 配置的 global 段中添加一行配置。建议添加第二行以设置更大的超时值,手动执行命令时此设置始终有益:
```text
global
stats socket /var/run/haproxy.sock mode 600 level admin
stats timeout 2m
```
也可以通过重复该行来添加多个统计信息套接字实例,并使其监听 TCP 端口而非 Unix 套接字。默认情况下从不这样做,因为存在安全隐患,但在某些情况下可能较为方便:
```text
global
stats socket /var/run/haproxy.sock mode 600 level admin
stats socket ipv4@192.168.0.1:9999 level admin
stats timeout 2m
```
要访问套接字,需要使用外部工具,例如“socat”。Socat 是一款功能强大的工具,可用于连接任意两个端点。我们使用它将终端连接到套接字,或将其与若干 stdin/stdout 管道连接,以供脚本使用。我们将主要使用以下两种语法:
```shell
# socat /var/run/haproxy.sock stdio
# socat /var/run/haproxy.sock readline
```
第一个用于脚本。可以将脚本的输出发送给 HAProxy,并将 HAProxy 的输出传递给另一个脚本。例如,这在获取计数器或攻击追踪信息时非常有用。
第二个仅适用于手动执行命令。其优势在于终端由 readline 库处理,支持行编辑和历史记录,当重复执行命令时(例如:监视计数器)非常方便。
套接字支持三种操作模式:
- 非交互式,静默模式
- 交互式,静默模式
- 交互式,带提示
非交互模式是 socat 与套接字连接时的默认模式。在此模式下,可发送单行内容。该行将作为整体被处理,响应会返回,并在响应结束时关闭连接。此模式通常由脚本和监控工具使用。在此模式下也可以发送多个命令,但需以分号(`;`)分隔。例如:
```shell
# echo "show info;show stat;show table" | socat /var/run/haproxy stdio
```
如果命令需要使用分号或反斜杠(例如在值中),则必须用反斜杠('\')进行转义。
交互模式允许在前一行命令执行完毕后发送新命令。
该模式存在两种变体:一种为静默模式,其行为与非交互模式类似,但套接字会等待新命令而非关闭;另一种在行首显示提示符(`\>`)。
对于高级工具,推荐使用交互模式;对于人类用户,推荐使用带提示符的模式。
可以使用 "prompt" 命令更改模式。默认情况下,该命令在交互模式与提示模式之间切换。在交互模式下输入 "prompt" 将切换至提示模式。该命令可选择性地指定以下特定模式之一:
- "n":非交互模式(执行单个命令后退出)
- "i":交互模式(执行多个命令,无提示符)
- "p":提示符模式(执行多个命令,带有提示符)
由于默认模式为非交互式,必须首先使用“prompt”命令切换模式,否则前一条命令将导致连接关闭。切换至非交互式模式后,同一行的所有命令执行完毕,连接将被关闭。
因此,在手动调试时,通常会从执行“prompt”命令开始:
```haproxy
# socat /var/run/haproxy readline
prompt
```
> show info ...
交互式工具可能更倾向于使用“prompt i”来切换至交互模式,而无需显示提示符。
可选地,提示符中可显示进程的运行时间。为启用此功能,使用命令 `prompt timed` 可启用提示符并切换时间显示状态。运行时间以格式 "d:hh:mm:ss" 显示,其中 "d" 表示天数,"hh"、"mm"、"ss" 分别表示以两位数字表示的小时、分钟和秒:
```haproxy
# socat /var/run/haproxy readline
prompt timed
```
[23:03:34:39]> show version 2.8-dev9-e5e622-18
[23:03:34:41]> quit
当在主 CLI 上设置定时提示时,提示符将显示当前选定进程的运行时间,因此该功能适用于主进程、当前工作进程或较早的工作进程:
```shell
master> prompt timed
[0:00:00:50] master> show proc
(...)
[0:00:00:58] master> @!11955 <-- master, switch to current worker
[0:00:01:03] 11955> @!11942 <-- current worker, switch to older worker
[0:00:02:17] 11942> @ <-- older worker, switch back to master
[0:00:01:10] master>
```
由于可同时发出多个命令,HAProxy 使用空行作为分隔符,以标记每个命令输出的结束,并确保没有任何命令会在输出中产生空行。因此,脚本可以轻松解析输出,即使多个命令在单行中通过管道传递。
部分命令可接受可选负载。若需为命令添加负载,首行必须以 "\<\<\n" 模式结尾。后续行将被视为负载内容,可包含任意行数。验证带负载的命令时,需以空行结尾。
负载内容的结束模式可自定义,以改变负载的结束方式。若需以非空行的方式结束负载,可在 `<<` 与 `\n` 之间设置自定义模式。除 `<<` 外,最多可使用 64 个字符,否则将不被视为有效负载。使用随机负载模式通常已足够。例如,使用包含空行和注释的 PEM 文件时:
```haproxy
# echo -e "set ssl cert common.pem <<%EOF%\n$(cat common.pem)\n%EOF%\n" | \
socat /var/run/haproxy.stat -
```
存在限制:模式 "\<\<" 不能紧接在行末最后一个单词之后。命令行长度不得超过 tune.bufsize,包括启动负载的模式,但不包含负载本身。负载大小默认限制为 128KB。可通过设置 "tune.cli.max-payload-size" 全局参数进行修改,但需注意相关注意事项。请注意,标记负载结束的模式也包含在此限制范围内。
在交互模式下输入负载时,提示符将从“> ”变为“+ ”。
当多个 HAProxy 进程在相同套接字上启动时,任意一个进程都可能接收请求,并输出其自身的统计信息。
当前支持的统计套接字命令列表如下。若发送了未知命令,HAProxy 将显示使用说明,提醒所有支持的命令。部分命令支持更复杂的语法,通常在出现错误时会说明命令中哪一部分无效。
部分命令需要更高权限才能执行。若权限不足,将收到错误提示“权限被拒绝”。请参阅配置手册中“bind”关键字行的“level”选项以获取更多信息。
**`abort ssl ca-file `**
```haproxy
abort ssl ca-file
```
中止并销毁临时 CA 文件更新事务。
另请参见“set ssl ca-file”和“commit ssl ca-file”。
**`abort ssl cert `**
```haproxy
abort ssl cert
```
中止并销毁临时 SSL 证书更新事务。
另请参见“set ssl cert”和“commit ssl cert”。
**`abort ssl crl-file `**
```haproxy
abort ssl crl-file
```
中止并销毁临时 CRL 文件更新事务。
另请参见“set ssl crl-file”和“commit ssl crl-file”。
**`acme renew `**
```haproxy
acme renew
```
启动一个使用指定证书名称的 ACME 证书生成任务。该证书必须关联至一个 acme 段,参见配置手册第 12.8 段“ACME”。另请参阅“acme status”。
**`acme status`**
```haproxy
acme status
```
显示所有使用 ACME 配置的证书的状态。
该命令以制表符分隔输出:
- HAProxy 中配置的证书名称
- 配置中使用的 acme 段
- acme 任务的状态,取值为 "Running"、"Scheduled" 或 "Stopped"
- 证书的 UTC 过期日期,格式为 ISO8601
- 相对过期时间(已过期则为 0d)
- 证书的 UTC 预定日期,格式为 ISO8601
- 相对预定时间(若处于 Running 状态则为 0d)
示例:
```shell
$ echo "@1; acme status" | socat /tmp/master.sock - | column -t -s $'\t'
# certificate section state expiration date (UTC) expires in scheduled date (UTC) scheduled in
ecdsa.pem LE Running 2020-01-18T09:31:12Z 0d 0h00m00s 2020-01-15T21:31:12Z 0d 0h00m00s
foobar.pem.rsa LE Scheduled 2025-08-04T11:50:54Z 89d 23h01m13s 2025-07-27T23:50:55Z 82d 11h01m14s
```
**`add acl [@] `**
```haproxy
add acl [@]
```
向 ACL `` 中添加一项。`` 为 \#`` 或由 "show acl" 返回的 ``。
该命令不会验证该项是否已存在。除非使用 "@``" 指定特定版本,否则条目将添加至当前 ACL 版本。该版本号必须事先通过 "prepare acl" 分配,且其值须位于 "show acl" 输出中报告的 "curr_ver" 与 "next_ver" 之间。使用特定版本号添加的条目,需在执行 "commit acl" 操作后方可生效匹配。但可使用 "show acl @``" 命令查阅,或通过 "clear acl @``" 命令清除。
若参考 `` 为与映射(map)同名的名称,则禁止使用此命令。此时应改用 "add map" 命令。
**`add backend from [mode ] [guid ]`**
```haproxy
add backend from [mode ] [guid ]
```
使用名称 `` 实例化一个新的后端代理。
仅可创建 TCP 或 HTTP 代理。所有设置均继承自 `` 默认代理实例。默认情况下,除非 `` 显式定义了后端模式,否则必须通过同名参数指定后端模式。如需,也可选择性地使用 GUID 参数。
可通过命令 `add server` 添加服务器。后端将以未发布状态初始化。确认已就绪可接收流量后,请使用 `publish backend` 命令发布新创建的实例。
所有命名的默认代理均可使用,前提是它们符合配置解析过程中应用的相同继承规则。不过存在一些例外情况,例如当模式既非 TCP 也非 HTTP 时。
此命令受限制,仅可在配置为“admin”级别的套接字上执行。
**`add map [@]