# HAProxy as root

**URL:** https://dietpi.com/forum/t/haproxy-as-root/25490
**Category:** Requests
**Created:** [15 September 2026 02:43 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490 "2026-09-15T02:43:36Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![gitzjoey](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/g/22d042/32.png) [@gitzjoey](https://dietpi.com/forum/u/gitzjoey)
#### Post date: [15 September 2026 02:43 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/1 "2026-09-15T02:43:36Z")

</div>

Hi,

regarding `haproxy.cfg`, the `global` section contains:

```auto
global
        maxconn 64
        chroot /var/lib/haproxy
        stats socket /run/haproxy.sock mode 660 level admin
        stats timeout 30s
        user root
        group root

```

I wanted to flag this because running the HAProxy worker process as `user root` and `group root` seems to present a few security issues:

1. **Defeating the `chroot` jail:** The config sets `chroot /var/lib/haproxy`, but a root user can break out of a `chroot` jail if remote code execution occurs.

2. **Principle of Least Privilege:** HAProxy only needs root permissions at startup to bind to privileged ports (80/443). After binding, best practice is to drop privileges to a non-root system account (e.g., `haproxy:haproxy`).

Is there a specific DietPi architectural reason why `user root` and `group root` are set in the default configuration?

If not, would it be better to change this default to `user haproxy` / `group haproxy` (and ensure `/var/lib/haproxy` ownership is updated accordingly) in future image builds or software installations?

thanks

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [15 September 2026 06:27 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/2 "2026-09-15T06:27:44Z")

</div>

something we would need to have a look into

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [17 September 2026 17:47 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/3 "2026-09-17T17:47:34Z")

</div>

done with [dietpi-software: HAProxy: switch from source build to own APT packages by Joulinar · Pull Request #8310 · MichaIng/DietPi · GitHub](https://github.com/MichaIng/DietPi/pull/8310)  
As well we will switch to an own deb package instead of compiling from source.

---

<div class="post-metadata">

### Author: ![gitzjoey](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/g/22d042/32.png) [@gitzjoey](https://dietpi.com/forum/u/gitzjoey)
#### Post date: [18 September 2026 06:00 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/4 "2026-09-18T06:00:12Z")

</div>

i see a PR is in place for next release of dietpi, as HAProxy user i’m very grateful.  
i see the fix of conf.d folder that not automatically created, the daemon removal. looking forward for the release.

1 note is on the log short and notice  
understand this might more on personal choice/preferences. but i prefer something like

log stderr format raw local0 info

but again its more on preferences.

---

<div class="post-metadata">

### Author: ![MichaIng](https://dietpi.com/forum/user_avatar/dietpi.com/michaing/32/7_2.png) [@MichaIng](https://dietpi.com/forum/u/MichaIng)
#### Post date: [18 September 2026 13:19 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/5 "2026-09-18T13:19:03Z")

</div>

> [@gitzjoey](#):
>
> but i prefer something like
> 
> log stderr format raw local0 info
> 
> but again its more on preferences.

The “short” format is explicitly made for systemd logging: HAProxy then sends logs with correct severity to the systemd journal, so that it can be filtered by that with `journalctl`, als messages are correctly colored based on severity. When using “raw”, it logs with the fixed default info severity and fixed facility, and the severity/level is instead shown as part of the log message, which is not great. IIRC, also the PID was shown in HAProxy’s message, i.e. doubled in journal, and correctly skipped in “short” format.

Is there anything you are missing with the “short” format?

---

<div class="post-metadata">

### Author: ![gitzjoey](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/g/22d042/32.png) [@gitzjoey](https://dietpi.com/forum/u/gitzjoey)
#### Post date: [18 September 2026 14:16 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/6 "2026-09-18T14:16:32Z")

</div>

sorry if i’m not clear enough, i’m more toward the notice/info level, since haproxy can consider as the gate, it would be better if the logs shows any kind of traffic from 200 - 500 status  
i’m ok with the short and color also personal preferences

---

<div class="post-metadata">

### Author: ![MichaIng](https://dietpi.com/forum/user_avatar/dietpi.com/michaing/32/7_2.png) [@MichaIng](https://dietpi.com/forum/u/MichaIng)
#### Post date: [18 September 2026 14:37 UTC](https://dietpi.com/forum/t/haproxy-as-root/25490/7 "2026-09-18T14:37:27Z")

</div>

If you need access logs, you can enable them. But I personally promote the oppinion of not logging sole access by default, but enabling this on demand, when facing issues, for diagnosis etc.

Though HTTP errors in logs would be good, for Fail2Ban etc. I got the impression, that HAProxy logs them with info severity as well. Maybe there is a way to raise the severity of request logs with 4xx/5xx response.
