Remote for Germany

Load balancers and high availability: HAProxy, keepalived, nginx

Load balancers are the bottleneck of every larger application: if they fail, everything behind them is unreachable, if they are misconfigured, response times and security suffer. For a client in an enterprise environment I designed multi-stage load balancer environments with keepalived and HAProxy, rolled them out across four stages with Ansible and connected them to monitoring, and I operate load balancing in the own data centre network of KernelHost GmbH.

For companies I build load balancers that deserve the name: as a redundant pair with a virtual IP, with clean TLS termination, sensible health checks and a configuration that comes from Git instead of the memory of a single administrator.

What is included

  • Architecture: layer 4 and layer 7 load balancing, direct server return with LVS, reverse proxy with HAProxy or nginx, DNS-based distribution across sites
  • High availability with keepalived (VRRP) and virtual IPs, failover within seconds without session loss
  • TLS termination with automatic certificates, HTTP/2 and HTTP/3, HSTS and secure cipher suites
  • Health checks, weighting, maintenance mode for individual backends, session persistence and rate limiting
  • Load balancing for databases (ProxySQL, PgBouncer, HAProxy) and for TCP services such as mail, VoIP and game servers
  • Kubernetes ingress and ingress controllers, MetalLB, upstream load balancers for OpenShift routers
  • Automation of the entire configuration with Ansible, rollout across development, test and production
  • Monitoring with Checkmk, Prometheus or Zabbix, load tests, capacity planning and documentation

Typical assignments

  • An online retailer replaces a single web server with an HAProxy pair with keepalived and three backends, updates have run without maintenance windows ever since.
  • A company with OpenShift clusters gets upstream load balancers across several stages, rolled out entirely from Ansible.
  • A SaaS application gets TLS termination, rate limiting and health checks centrally on the load balancer instead of in every instance.
  • Sporadic connection drops are traced back to mismatched timeouts between load balancer and backends and fixed.

Process

  1. Request

    Describe your needs briefly via the form, WhatsApp or the live chat.

  2. Assessment

    Within one business day you receive an assessment with effort, price and a proposed date.

  3. Implementation

    I do the work personally, remotely via secured access or on site, and keep you updated throughout.

  4. Handover and invoice

    Documented handover, then an invoice from KernelHost GmbH with convenient payment via kernelhost.com.

Questions about this service

HAProxy, nginx or LVS: which is the right choice?

HAProxy for flexible layer 7 rules, health checks and statistics, nginx when a web server or caching is needed anyway, LVS with direct server return for very high throughput on layer 4. Often the combination makes sense, which I clarify based on your application.

Do we need our own hardware for this?

No. Two small virtual machines are enough for most applications, whether in your own data centre, at a cloud provider or on servers of KernelHost GmbH. The only requirement is that both nodes can take over the same virtual IP.

Can you also look after the load balancers on an ongoing basis?

Yes. The configuration lives in Git, changes run through Ansible, and monitoring reports failures of backends or certificates. Maintenance and changes are billed by effort or from an hour bundle, without a base fee.

Remote for companies across Germany, alignment via video call, ticket or chat.

Ready to discuss your project?

Describe your project in a few sentences. You will receive an assessment with effort and price within one business day.