No description
  • JavaScript 69.8%
  • Python 27.7%
  • Shell 1.3%
  • CSS 1%
  • HTML 0.2%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-26 18:16:57 +00:00
deploy Add security audit and CrowdSec views 2026-09-21 20:53:34 +02:00
ham Merge remote security views with audit CPU fix 2026-09-26 18:16:57 +00:00
static Add security audit and CrowdSec views 2026-09-21 20:53:34 +02:00
.gitignore Initialize HAProxy Manager fork with probe fix 2026-09-21 06:28:10 +00:00
app.py Fix audit tail CPU from per-line SQLite pruning 2026-09-26 18:16:21 +00:00
install.sh Initialize HAProxy Manager fork with probe fix 2026-09-21 06:28:10 +00:00
LICENSE Initialize HAProxy Manager fork with probe fix 2026-09-21 06:28:10 +00:00
README.md Add security audit and CrowdSec views 2026-09-21 20:53:34 +02:00
test_auditlog.py Fix audit tail CPU from per-line SQLite pruning 2026-09-26 18:16:21 +00:00
VERSION Add security audit and CrowdSec views 2026-09-21 20:53:34 +02:00

HAProxy Manager

This repository is a downstream fork of HAProxy Manager, the original product.

The upstream GNU General Public License, version 3 or later, is retained for this fork.

Differences from upstream

  • ham/probe.py changes published-URL watchdog probes: when HTTPS is served by a loopback frontend behind a public TCP/SNI listener on port 443, probes use the public port 443 with the service hostname instead of probing the internal PROXY-protocol port. This prevents healthy services from being reported as not answering.
  • ham/auditlog.py adds a read-only Traffic Audit page. It parses HAProxy L4/L7 access-log and event records into a node-local SQLite database with 30-day retention, pagination and filters for log kind, client IP and time range.
  • ham/adminaudit.py adds a structured Admin Audit page. Mutating UI/API requests are recorded with actor, source IP, method, path, resource and result in a separate node-local 30-day SQLite database.
  • ham/crowdsec.py adds CrowdSec Decisions, Whitelist/Blacklist and read-only AppSec pages. Decisions can be listed, added and removed through cscli; the whitelist editor updates the local CrowdSec parser whitelist and reloads CrowdSec. These operations do not modify haproxy.cfg or reload HAProxy.
  • The navigation adds a Security section for Traffic Audit, Admin Audit, CrowdSec Decisions, CrowdSec Whitelist/Blacklist and CrowdSec AppSec. The AppSec view reports configured CRS/AppSec state, metrics availability and recent alerts without changing CrowdSec state.