HAProxy: Logs without persistent client IP
HAProxy sees the client IP technically as a reverse proxy. What matters is whether it then ends up permanently in normal access logs or forwarded headers.
Requirements
Access to the proxy configuration; Save existing log definitions before changing them.
Consciously define log format
HAProxy supports freely defined log formats. For a data-efficient request log, do not include any client IP fields or unnecessary request headers, cookies or query data. Check standard formats before use instead of adopting them unchanged.
Separate the origin from the visitor IP
If the application does not need the real visitor IP, do not pass it on to the origin via X-Forwarded-For, Forwarded or comparable custom headers. If possible, leave security decisions that can be made at the proxy there.
Treat security logging separately
Short-term data for attack detection and abuse prevention is a different level than long-term general visitor logging. Therefore, document the purpose, scope and storage separately.
Test
Generate test calls and check which client data is actually logged or passed on.
Dismantling
If there are problems, restore the saved log configuration and test again.
Additional log levels
Additionally Check hoster, proxy and security logs separately; A cleaned HAProxy log alone does not prove that the entire chain is IP-free.
Related guides
Sources and verification
This guide is based on multiple current sources. Vendor documentation is not treated as proof that every concrete installation automatically follows the same privacy characteristics.
Important: IP processing is not IP storage
An IP address has to be processed to establish and deliver a network connection. Hosting providers, firewalls or DDoS protection may also process or retain it for a limited time for security purposes. No Logging distinguishes this security layer from unnecessary persistent visitor logging by the website, application and ordinary access logs.