HAProxy Edge Proxy

Publish services from private or NAT workloads through a controlled HAProxy edge listener.

One-Click documentation · Step-by-step guide

The edge proxy exposes selected services from private guests without requiring a public IP on every workload. HAProxy remains at the edge and forwards traffic to the selected internal destination.

Web Publishing

one-click --proxy --target analytics-vm --website dashboard.example.com --proto https

TCP Publishing

one-click --proxy --target web1 --source 22 --port 8822

Operational Controls

  • Publish only the protocol and port actually required.
  • Keep TLS termination design explicit: edge termination and end-to-end TLS have different certificate responsibilities.
  • Validate HAProxy syntax before reload.
  • Record the mapping so guest lifecycle changes do not leave orphaned listeners.