sudo wget -qO /usr/share/keyrings/HAPROXY-key-community.asc https://pks.haproxy.com/linux/community/RPM-GPG-KEY-HAProxy
echo "deb [arch=amd64 signed-by=/usr/share/keyrings/HAPROXY-key-community.asc] https://www.haproxy.com/download/haproxy/performance/debian/ha34 trixie main" | sudo tee /etc/apt/sources.list.d/haproxy.list
sudo apt update && sudo apt upgrade -y
sudo apt install haproxy-awslc -y
haproxy -v
sudo systemctl start haproxy sudo systemctl enable haproxy
/etc/haproxy/haproxy.cfg file with this HAProxy Configuration configuration.sudo haproxy -c -f /etc/haproxy/haproxy.cfg
sudo systemctl restart haproxy
tail -f /var/log/apache2/your-site-access.log
rm /etc/apache2/sites-enabled/0xx-your-site.conf
timeout http-keep-alive or timeout client/server settingsoption http-server-close to the backend server definition in /etc/haproxy/haproxy.cfg during transitionsudo certbot delete --cert-name yourdomain.com /etc/letsencrypt/renewal/mv yourdomain.com.conf /etc/letsencrypt/renewal/yourdomain.com.disabled
haproxy.cfg.certbot config file with a modified rule frontend public_inbound_http and a new backend rule backend http_server_certbot and copy it to haproxy.cfg:frontend public_inbound_http
bind *:80
mode http
default_backend http_server_certbot
backend http_server_certbot
mode http
cookie SERVERID insert indirect nocache
server calypso 192.168.3.101:80 check
sudo systemctl reload haproxy
sudo certbot renewhaproxy.cfg and reload the proxy rulessudo a2enmod remoteip
/etc/apache2/conf-available/remoteip.conf and define your HAProxy server as a trusted internal proxy:RemoteIPHeader X-Forwarded-For RemoteIPInternalProxy 192.168.3.50 # this is your HAProxy private IP
sudo a2enconf remoteip
LogFormat "%a %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined
sudo apache2ctl configtest sudo systemctl restart apache2
send-proxy or send-proxy-v2 to your backend server line:backend passthrough_server
mode tcp
server web1 192.168.3.90:443 send-proxy check
tcp-request connection reject) I chose a different approach. I linked a temporary domain name to the backend server and transfer HTTP to access restricted sub-pages like phpmyadmin. For the configuration follow the settings used for backuppc.sudo systemctl restart haproxy
RemoteIPProxyProtocol directive:<VirtualHost *:443>
ServerName example.com
# Enable Proxy Protocol interpretation
RemoteIPProxyProtocol On
RemoteIPProxyProtocolExceptions 127.0.0.1
# ... your SSL and document root settings ...
</VirtualHost>
/etc/apache2/conf-available/bco-trusted-ip.conf:<RequireAny>
# Local subnet
Require ip 192.168.1
# Fixed ip (if you have any)
Require ip my.fixed.ip.addr
</RequireAny>
/etc/apache2/conf-available/bco-current-ip.conf.Include to every directory you want to restrict access to in your <VirtualHost> file:...
<Directory /usr/share/phpmyadmin>
Include conf-available/bco-trusted-ip.conf
Include conf-available/bco-current-ip.conf
</Directory>
...
IP=$(curl -s https://api.ipify.org) && ssh -p 50322 your.domain.name "echo \"Require ip $IP\" > /etc/apache2/conf-available/bco-current-ip.conf && sudo /usr/bin/systemctl reload apache2" ssh -p 22 your.domain.name "echo \"\" > /etc/apache2/conf-available/bco-current-ip.conf && sudo /usr/bin/systemctl reload apache2"
apache in /etc/sudoers.d so <user> can reload the apache config as root without password:vim /etc/sudoers.d/apache <user> ALL=(root) NOPASSWD: /usr/bin/systemctl reload apache2
#!/bin/bash
# bco, 2026-09-20
# update my current IP address in Apache config
#
IP=$(curl -s https://api.ipify.org)
# Regex pattern matching 0-255 for individual octets
octet='(25[0-5]|2[0-4][0-9]|1[0-9]{2}|[1-9][0-9]|[0-9])'
pattern="^${octet}\.${octet}\.${octet}\.${octet}$"
if [[ $IP =~ $pattern ]]; then
ssh -p 22 your.domain.name "echo \"Require ip $IP\" > /etc/apache2/conf-available/bco-current-ip.conf && sudo /usr/bin/systemctl reload apache2"
else
echo "Invalid IP address"
sleep 3
exit 1
fi
exit 0
C:\Windows\System32\wsl.exe bash ~/batch/updateApacheIP