Files
coredns/man/coredns-proxyproto.7
Ben Kochie 311a9915da Improve RFC links (#8612)
The `tools.ietf.org` site now redirects to `www.rfc-editor.org`.
* Update various URLs to the new site.
* Make links to `www.rfc-editor.org` consistent.

Signed-off-by: SuperQ <superq@gmail.com>
2026-10-08 10:21:06 +02:00

147 lines
3.5 KiB
Groff

.\" Generated by Mmark Markdown Processer - mmark.miek.nl
.TH "COREDNS-PROXYPROTO" 7 "October 2026" "CoreDNS" "CoreDNS Plugins"
.SH "NAME"
.PP
\fIproxyproto\fP - add PROXY protocol
\[la]https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt\[ra] support.
.SH "DESCRIPTION"
.PP
This plugin adds support for the PROXY protocol version 1 and 2. It allows CoreDNS to receive
connections from a load balancer or proxy that uses the PROXY protocol to forward the original
client's IP address and port information.
.SH "SYNTAX"
.PP
.RS
.nf
proxyproto {
allow <CIDR...>
default <use|ignore|reject|skip>
udp\_session\_tracking <duration> [max\_sessions]
}
.fi
.RE
.PP
If \fB\fCallow\fR is unspecified, PROXY protocol headers are accepted from all IP addresses.
The \fB\fCdefault\fR option controls how connections from sources not listed in \fB\fCallow\fR are handled.
If \fB\fCdefault\fR is unspecified, it defaults to \fB\fCignore\fR.
The possible values are:
.IP \(bu 4
\fB\fCuse\fR: accept and use PROXY protocol headers from these sources
.IP \(bu 4
\fB\fCignore\fR: accept and ignore PROXY protocol headers from other sources
.IP \(bu 4
\fB\fCreject\fR: reject connections with PROXY protocol headers from other sources
.IP \(bu 4
\fB\fCskip\fR: skip PROXY protocol processing for connections from other sources, treating them as normal connections preserving the PROXY protocol headers.
.PP
The \fB\fCudp_session_tracking <duration> [max_sessions]\fR option enables UDP session state tracking
for Cloudflare Spectrum's PROXY Protocol v2 over UDP. Spectrum sends the PPv2 header as a
standalone first datagram (with no DNS payload). Subsequent datagrams from the same client arrive
without any header. When this option is set to a positive duration, the real client address from
the header-only datagram is cached (keyed by the Spectrum-side remote address) for that duration
and automatically applied to all subsequent headerless datagrams within that window. The TTL is
refreshed on each matching packet. The optional \fB\fCmax_sessions\fR argument caps the number of
concurrent sessions in the LRU cache (default: 10240). This option has no effect for TCP
connections.
.SH "EXAMPLES"
.PP
In this configuration, we allow PROXY protocol connections from all IP addresses:
.PP
.RS
.nf
\&. {
proxyproto
forward . /etc/resolv.conf
}
.fi
.RE
.PP
In this configuration, we only allow PROXY protocol connections from the specified CIDR ranges
and ignore proxy protocol headers from other sources:
.PP
.RS
.nf
\&. {
proxyproto {
allow 192.168.1.1/32 192.168.0.1/32
}
forward . /etc/resolv.conf
}
.fi
.RE
.PP
In this configuration, we only allow PROXY protocol headers from the specified CIDR ranges and reject
connections without valid PROXY protocol headers from those sources:
.PP
.RS
.nf
\&. {
proxyproto {
allow 192.168.1.1/32
default reject
}
forward . /etc/resolv.conf
}
.fi
.RE
.PP
In this configuration, we enable UDP session tracking for Cloudflare Spectrum's PPv2-over-UDP
with a 28-second TTL (slightly shorter than Spectrum's 30-second UDP idle timeout) and the
default session cap of 10240:
.PP
.RS
.nf
\&. {
proxyproto {
allow 192.168.1.1/32
udp\_session\_tracking 28s
}
forward . /etc/resolv.conf
}
.fi
.RE
.PP
In this configuration, the session cap is raised to 20480:
.PP
.RS
.nf
\&. {
proxyproto {
allow 192.168.1.1/32
udp\_session\_tracking 28s 20000
}
forward . /etc/resolv.conf
}
.fi
.RE