Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lua scripts in HAProxy - help!

    Scheduled Pinned Locked Moved Cache/Proxy
    3 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • senseivitaS
      senseivita
      last edited by

      I'm attempting to install Authelia, hopefully leave ADFS behind, but it requires a few of Lua scripts which I found already but I keep getting a notice they aren't there.

      I don't know if Im putting in the wrong names or if I actually have to put the config the will call them: lua-load <path>, or if it there is really missing one like it says in the warning.

      But, errors appears as soon as I add scripts despite not having adding any config in the global or frontend sections, it suggests pfSense's implementation of HAProxy calls them automatically, and very confusing/contradictory.

      When I'm snooping around dev circles, Python, Perl, Ruby, Java (🤢)… are names I see thrown around more often, all the Cs with older bigger systems, but Lua…nope, only next to HAProxy. I don't suppose it really comes with pfSense as that other docu says, does it??

      I took a few screenshots of the errors:
      Screen Shot 2020-10-06 at 23.58.50.png

      Is the JSON Lua library in pfSense for real?

      Thanks

      Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

      1 Reply Last reply Reply Quote 0
      • L
        lgwapnitsky
        last edited by

        Did you ever get authelia to work with pfsense/haproxy? I'm looking into it now, and I'm finding the documentation to be sparse

        senseivitaS 1 Reply Last reply Reply Quote 0
        • senseivitaS
          senseivita @lgwapnitsky
          last edited by

          @lgwapnitsky No, I moved to a dedicated host for HAProxy and just about to deploy I realized it doesn't have that robust of support for directory accounts. I use Active Directory.

          Also, since I asked pfSense 2.5 is came out and it's got a ton of new stuff: it now has the current (or very close to current) HAProxy, supports TLS1.3. I'll try again and come back if I'm successful, good luck to you too! :)

          ________

          PS: If you're open to alternatives for authentication, take a look at Keycloak from (backed by) Red Hat. It does federation, clustering, it provides many clients (to integrate with). OpenID Connect, OpenID, LDAPS, SAML, hardwarekeys/tokens, socials, SMS, you name it, it does it all and it doesn't even need installation, you just run the WildFly (or Tomcat/JBoss/etc..) servlet. Just charge an iPad or 'cause you'll be doing plenty or reading. It's not hard though. :)

          Missing something? Word endings, maybe? I included a free puzzle in this msg if you solv--okay, I'm lying. It's dyslexia, makes me do that, sorry! Just finish the word; they're rarely misspelled, just incomplete. Yeah-yeah-I know. Same thing.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.