Building a High-Availability Reverse Proxy with HAProxy and Keepalived: A Zero-Downtime Infrastructure Strategy for Critical Landing Pages
Introduction: The Cost of Infrastructure Downtime
In modern digital marketing and enterprise lead generation, a landing page is more than just a single web page; it is a critical revenue funnel. When an organization launches a high-budget marketing campaign, a sudden influx of traffic can easily overwhelm a standard Virtual Private Server (VPS) setup. Worse yet, if the primary server hosting your landing page encounters a hardware failure, network outage, or software crash, your campaign grinds to a halt. This results in wasted ad spend, lost conversion opportunities, and structural damage to brand reputation.
To mitigate these risks, enterprise IT infrastructures rely on high availability (HA). This technical guide explores how to construct a robust, high-availability reverse proxy cluster utilizing two industry-standard open-source tools: HAProxy and Keepalived. By deploying this architecture across multiple VPS instances, you can establish a zero-downtime strategy that ensures your critical landing pages remain continuously accessible, even during localized server failures.
Understanding the Architecture: HAProxy and Keepalived
Before diving into the configuration, it is essential to understand the structural components of a high-availability reverse proxy setup and how they interact to protect your backend web servers.
The Role of HAProxy
HAProxy (High Availability Proxy) is a world-class, open-source TCP/HTTP load balancer and proxying solution. Positioned in front of your backend web servers, HAProxy acts as a traffic cop. It accepts incoming client requests and distributes them across multiple backend nodes based on predefined algorithms (such as Round Robin or Least Connections). Beyond simple load balancing, HAProxy performs continuous health checks on backend servers, automatically rerouting traffic away from any node that becomes unresponsive.
The Role of Keepalived and VRRP
While HAProxy effectively distributes traffic across backend servers, it introduces a new vulnerability: if the VPS running HAProxy goes down, your entire application goes down with it. This is known as a Single Point of Failure (SPOF).
To eliminate this vulnerability, we introduce Keepalived. Keepalived uses the Virtual Router Redundancy Protocol (VRRP) to monitor the health of the load balancers themselves. It allows two or more distinct VPS instances to share a single, dynamic IP address known as a Virtual IP (VIP). At any given moment, one HAProxy node is designated as the MASTER, holding the VIP and handling all incoming traffic. Meanwhile, a second node sits in BACKUP mode. If the master node fails, Keepalived instantly detects the outage and transitions the VIP to the backup node in milliseconds, ensuring uninterrupted service delivery.
Prerequisites and Environment Setup
To implement this high-availability architecture, you will require the following infrastructure components:
- Two (2) VPS Instances: These will serve as your redundant proxy nodes. For clarity, we will refer to them as
Proxy-Node-01andProxy-Node-02. - Two (2) or more Backend Web Servers: These servers will host the actual landing page files (running Nginx, Apache, or a Dockerized web application).
- One (1) Floating/Virtual IP (VIP): A static, publicly routable IP address provided by your VPS hosting provider that can be dynamically reassigned via software.
- Operating System: Ubuntu 22.04 LTS or Debian 12 installed on all infrastructure nodes.
- Privileges: Root or
sudoaccess on all servers.
Step-by-Step Configuration Guide
Step 1: Installing and Configuring HAProxy
First, we must install and configure HAProxy on both Proxy-Node-01 and Proxy-Node-02. Execute the following commands on both proxy servers:
sudo apt update
sudo apt install haproxy -yOnce installed, back up the default configuration file and open a new one for editing:
sudo cp /etc/haproxy/haproxy.cfg /etc/haproxy/haproxy.cfg.bak
sudo nano /etc/haproxy/haproxy.cfgInsert the following structural configuration. This setup configures HAProxy to listen on port 80 and balance traffic across two backend web servers using the round-robin method, while also enabling an administrative statistics dashboard.
Note: Replace the placeholder backend IP addresses with the actual internal IP addresses of your web servers.
global
log /dev/log local0
log /dev/log local1 notice
chroot /var/lib/haproxy
user haproxy
group haproxy
daemon
defaults
log global
mode http
option httplog
option dontlognull
timeout connect 5000ms
timeout client 50000ms
timeout server 50000ms
frontend landing_page_front
bind *:80
stats uri /haproxy?stats
default_backend landing_page_back
backend landing_page_back
balance roundrobin
option httpchk GET /health.html
server web_server_01 10.0.0.10:80 check
server web_server_02 10.0.0.11:80 checkAfter saving the file, verify the configuration syntax and restart the service:
sudo haproxy -c -f /etc/haproxy/haproxy.cfg
sudo systemctl restart haproxy
sudo systemctl enable haproxyStep 2: Installing and Configuring Keepalived
With HAProxy running, we must now configure Keepalived to manage the Virtual IP across our two proxy nodes. Install Keepalived on both proxy instances:
sudo apt install keepalived -yNext, configure the primary proxy node (Proxy-Node-01). Create the configuration file:
sudo nano /etc/keepalived/keepalived.confPopulate the file with the following directive block, ensuring you replace eth0 with your system's actual network interface name and 203.0.113.50 with your allocated Virtual IP address:
vrrp_script check_haproxy {
script "/usr/bin/killall -0 haproxy"
interval 2
weight 2
}
vrrp_instance VI_1 {
state MASTER
interface eth0
virtual_router_id 51
priority 101
advert_int 1
authentication {
auth_type PASS
auth_pass Secr3tPa$$word
}
virtual_ipaddress {
203.0.113.50
}
track_script {
check_haproxy
}
}Now, configure the secondary proxy node (Proxy-Node-02). Create the same file but modify the state to BACKUP and lower the priority value to 100:
vrrp_script check_haproxy {
script "/usr/bin/killall -0 haproxy"
interval 2
weight 2
}
vrrp_instance VI_1 {
state BACKUP
interface eth0
virtual_router_id 51
priority 100
advert_int 1
authentication {
auth_type PASS
auth_pass Secr3tPa$$word
}
virtual_ipaddress {
203.0.113.50
}
track_script {
check_haproxy
}
}To ensure Keepalived can bind to the shared Virtual IP address even if it is not currently assigned to the local interface, add the following kernel directive to /etc/sysctl.conf on both servers:
net.ipv4.ip_nonlocal_bind=1Apply the system changes and start Keepalived:
sudo sysctl -p
sudo systemctl start keepalived
sudo systemctl enable keepalivedTesting the Failover Mechanism
To validate the reliability of your zero-downtime architecture, you must perform a failover simulation. Point your domain's DNS A-record to the Virtual IP address (VIP) configured in Keepalived.
- Verify that your landing page loads successfully under normal operating conditions.
- Log into
Proxy-Node-01(the MASTER node) and simulate a failure by stopping the HAProxy service:sudo systemctl stop haproxy - Monitor your website traffic or run a continuous
curlloop in your terminal. You will observe that the Virtual IP instantly shifts toProxy-Node-02, resulting in zero dropped requests. - Review the system logs on the backup server using
journalctl -u keepalivedto confirm it transitioned to theMASTERstate.
Conclusion: Maximizing Campaign ROI with Infrastructure Stability
Setting up a high-availability reverse proxy using HAProxy and Keepalived provides a bulletproof foundation for enterprise marketing infrastructure. By placing a redundant load-balancing layer in front of your applications, you shield your business from server instability and structural traffic bottlenecks. While deploying an HA cluster requires a modest initial investment in VPS resources and configuration time, the return on investment is realized the moment a hardware failure occurs without disrupting a single user. Implementing these enterprise-grade infrastructure practices guarantees that your landing pages remain fast, secure, and permanently online.
