mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 12:05:22 -04:00
The `tools.ietf.org` site now redirects to `www.rfc-editor.org`. * Update various URLs to the new site. * Make links to `www.rfc-editor.org` consistent. Signed-off-by: SuperQ <superq@gmail.com>
147 lines
3.5 KiB
Groff
147 lines
3.5 KiB
Groff
.\" Generated by Mmark Markdown Processer - mmark.miek.nl
|
|
.TH "COREDNS-PROXYPROTO" 7 "October 2026" "CoreDNS" "CoreDNS Plugins"
|
|
|
|
.SH "NAME"
|
|
.PP
|
|
\fIproxyproto\fP - add PROXY protocol
|
|
\[la]https://www.haproxy.org/download/1.8/doc/proxy-protocol.txt\[ra] support.
|
|
|
|
.SH "DESCRIPTION"
|
|
.PP
|
|
This plugin adds support for the PROXY protocol version 1 and 2. It allows CoreDNS to receive
|
|
connections from a load balancer or proxy that uses the PROXY protocol to forward the original
|
|
client's IP address and port information.
|
|
|
|
.SH "SYNTAX"
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
proxyproto {
|
|
allow <CIDR...>
|
|
default <use|ignore|reject|skip>
|
|
udp\_session\_tracking <duration> [max\_sessions]
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
If \fB\fCallow\fR is unspecified, PROXY protocol headers are accepted from all IP addresses.
|
|
The \fB\fCdefault\fR option controls how connections from sources not listed in \fB\fCallow\fR are handled.
|
|
If \fB\fCdefault\fR is unspecified, it defaults to \fB\fCignore\fR.
|
|
The possible values are:
|
|
|
|
.IP \(bu 4
|
|
\fB\fCuse\fR: accept and use PROXY protocol headers from these sources
|
|
.IP \(bu 4
|
|
\fB\fCignore\fR: accept and ignore PROXY protocol headers from other sources
|
|
.IP \(bu 4
|
|
\fB\fCreject\fR: reject connections with PROXY protocol headers from other sources
|
|
.IP \(bu 4
|
|
\fB\fCskip\fR: skip PROXY protocol processing for connections from other sources, treating them as normal connections preserving the PROXY protocol headers.
|
|
|
|
|
|
.PP
|
|
The \fB\fCudp_session_tracking <duration> [max_sessions]\fR option enables UDP session state tracking
|
|
for Cloudflare Spectrum's PROXY Protocol v2 over UDP. Spectrum sends the PPv2 header as a
|
|
standalone first datagram (with no DNS payload). Subsequent datagrams from the same client arrive
|
|
without any header. When this option is set to a positive duration, the real client address from
|
|
the header-only datagram is cached (keyed by the Spectrum-side remote address) for that duration
|
|
and automatically applied to all subsequent headerless datagrams within that window. The TTL is
|
|
refreshed on each matching packet. The optional \fB\fCmax_sessions\fR argument caps the number of
|
|
concurrent sessions in the LRU cache (default: 10240). This option has no effect for TCP
|
|
connections.
|
|
|
|
.SH "EXAMPLES"
|
|
.PP
|
|
In this configuration, we allow PROXY protocol connections from all IP addresses:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
\&. {
|
|
proxyproto
|
|
forward . /etc/resolv.conf
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
In this configuration, we only allow PROXY protocol connections from the specified CIDR ranges
|
|
and ignore proxy protocol headers from other sources:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
\&. {
|
|
proxyproto {
|
|
allow 192.168.1.1/32 192.168.0.1/32
|
|
}
|
|
forward . /etc/resolv.conf
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
In this configuration, we only allow PROXY protocol headers from the specified CIDR ranges and reject
|
|
connections without valid PROXY protocol headers from those sources:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
\&. {
|
|
proxyproto {
|
|
allow 192.168.1.1/32
|
|
default reject
|
|
}
|
|
forward . /etc/resolv.conf
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
In this configuration, we enable UDP session tracking for Cloudflare Spectrum's PPv2-over-UDP
|
|
with a 28-second TTL (slightly shorter than Spectrum's 30-second UDP idle timeout) and the
|
|
default session cap of 10240:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
\&. {
|
|
proxyproto {
|
|
allow 192.168.1.1/32
|
|
udp\_session\_tracking 28s
|
|
}
|
|
forward . /etc/resolv.conf
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|
|
.PP
|
|
In this configuration, the session cap is raised to 20480:
|
|
|
|
.PP
|
|
.RS
|
|
|
|
.nf
|
|
\&. {
|
|
proxyproto {
|
|
allow 192.168.1.1/32
|
|
udp\_session\_tracking 28s 20000
|
|
}
|
|
forward . /etc/resolv.conf
|
|
}
|
|
|
|
.fi
|
|
.RE
|
|
|