# HAProxy SOPA Bouncer Installation failure

**URL:** <https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715>\
**Category:** crowdsec\
**Created:** [November 12, 2025, 7:12pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715 "2025-11-12T19:12:29Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![wrathjen](https://avatars.discourse-cdn.com/v4/letter/w/3bc359/32.png) [@wrathjen](https://discourse.crowdsec.net/u/wrathjen)\
**Post date:** [November 12, 2025, 7:12pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/1 "2025-11-12T19:12:29Z")

</div>

Ubuntu 24.04.3 LTS. Non pro  
CrowdSec installed version v1.7.3

fresh-ish install using CrowdSec repos

cp: cannot stat ‘/usr/share/doc/crowdsec-haproxy-spoa-bouncer/examples/crowdsec.cfg’: No such file or directory  
dpkg: error processing package crowdsec-haproxy-spoa-bouncer (–configure):  
installed crowdsec-haproxy-spoa-bouncer package post-installation script subprocess returned error exit status 1  
Errors were encountered while processing:  
crowdsec-haproxy-spoa-bouncer  
needrestart is being skipped since dpkg has failed  
E: Sub-process /usr/bin/dpkg returned an error code (1)

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [November 13, 2025, 7:25am UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/2 "2025-11-13T07:25:35Z")

</div>

Can you advise us which platform this is on? plus the version that was stated to be installed (should be 0.1.2)

eg: amd64

---

<div class="post-metadata">

**Author:** ![wrathjen](https://avatars.discourse-cdn.com/v4/letter/w/3bc359/32.png) [@wrathjen](https://discourse.crowdsec.net/u/wrathjen)\
**Post date:** [November 16, 2025, 6:03am UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/3 "2025-11-16T06:03:42Z")

</div>

v0.1.2-debian-pragmatic-amd64

---

<div class="post-metadata">

**Author:** ![wrathjen](https://avatars.discourse-cdn.com/v4/letter/w/3bc359/32.png) [@wrathjen](https://discourse.crowdsec.net/u/wrathjen)\
**Post date:** [November 16, 2025, 6:46am UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/4 "2025-11-16T06:46:24Z")

</div>

I was able to get the install to finish by creating a blank file at /usr/share/doc/crowdsec-haproxy-spoa-bouncer/examples/crowdsec.cfg and continue with configuration. I am however now unable to get the configuration to validate using the cdn based configuration from the documentation.

---

<div class="post-metadata">

**Author:** ![wrathjen](https://avatars.discourse-cdn.com/v4/letter/w/3bc359/32.png) [@wrathjen](https://discourse.crowdsec.net/u/wrathjen)\
**Post date:** [November 16, 2025, 6:47am UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/5 "2025-11-16T06:47:14Z")

</div>

I have removed the lua based information as it does not appear to be installed in the current version.

sudo haproxy -c -f /etc/haproxy/haproxy.cfg  
[NOTICE] (192571) : haproxy version is 2.8.5-1ubuntu3.4  
[NOTICE] (192571) : path to executable is /usr/sbin/haproxy  
[ALERT] (192571) : config : parsing [/etc/haproxy/haproxy.cfg:98] : ‘filter’ : ‘No SPOE agent found in file /etc/haproxy/crowdsec.cfg’  
[ALERT] (192571) : config : parsing [/etc/haproxy/haproxy.cfg:107]: ‘http-request’ expects ‘wait-for-handshake’, ‘set-log-level’, ‘set-nice’, ‘use-service’, ‘sc-add-gpc(_)', 'sc-inc-gpc(_)’, ‘sc-inc-gpc0(_)', 'sc-inc-gpc1(_)’, ‘sc-set-gpt(_)', 'sc-set-gpt0(_)’, ‘send-spoe-group’, ‘do-resolve(_)', ‘cache-use’, 'add-acl(_)’, ‘add-header’, ‘allow’, ‘auth’, ‘capture’, ‘del-acl(_)', ‘del-header’, 'del-map(_)’, ‘deny’, ‘disable-l7-retry’, ‘early-hint’, ‘normalize-uri’, ‘redirect’, ‘reject’, ‘replace-header’, ‘replace-path’, ‘replace-pathq’, ‘replace-uri’, ‘replace-value’, ‘return’, ‘set-header’, ‘set-map(_)', ‘set-method’, ‘set-path’, ‘set-pathq’, ‘set-query’, ‘set-uri’, ‘strict-mode’, ‘tarpit’, 'track-sc(_)’, ‘set-timeout’, ‘wait-for-body’, ‘set-var-fmt(_)', 'set-var(_)’, ‘unset-var(\*)’, ‘set-dst’, ‘set-dst-port’, ‘set-mark’, ‘set-src’, ‘set-src-port’, ‘set-tos’, ‘silent-drop’, ‘set-priority-class’, ‘set-priority-offset’, ‘set-bandwidth-limit’, but got ‘lua.crowdsec\_handle’.  
[ALERT] (192571) : config : Error(s) found in configuration file : /etc/haproxy/haproxy.cfg

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [November 17, 2025, 8:10am UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/6 "2025-11-17T08:10:07Z")

</div>

Okay so creating a blank file means that the cp will move a blank file to `/etc/haproxy/crowdsec.cfg` you need to ensure this content is within it [here](https://raw.githubusercontent.com/crowdsecurity/cs-haproxy-spoa-bouncer/refs/heads/main/config/crowdsec.cfg).

Then we need the lua to be able to render runtime templates so the lua files need to be placed `/usr/lib/crowdsec-haproxy-spoa-bouncer/lua` directory and [these lua files](https://github.com/crowdsecurity/cs-haproxy-spoa-bouncer/tree/main/lua) need to be placed within that folder.

Once that is done you need to ensure the [templates](https://github.com/crowdsecurity/cs-haproxy-spoa-bouncer/tree/main/templates) also exist in the right location `/var/lib/cs-haproxy-spoa-bouncer/html`

However, we cant replicate this issue can you **MAKE SURE** you have ran our repository installation script EG:

```auto
curl -s https://install.crowdsec.net/ | sudo sh

```

and that the hash matches below:

```bash
$ md5sum /etc/apt/sources.list.d/crowdsec_crowdsec.list
efd76326c2cd7f9308512ccc5f0831aa /etc/apt/sources.list.d/crowdsec_crowdsec.list

```

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [November 17, 2025, 3:42pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/7 "2025-11-17T15:42:13Z")

</div>

Okay I found the issue, this will resolved for version `0.2.0` until then you must follow the manual installation steps above.

---

<div class="post-metadata">

**Author:** ![wrathjen](https://avatars.discourse-cdn.com/v4/letter/w/3bc359/32.png) [@wrathjen](https://discourse.crowdsec.net/u/wrathjen)\
**Post date:** [November 17, 2025, 7:31pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/8 "2025-11-17T19:31:39Z")

</div>

Awesome! Out of curiosity any idea when that will be released?

---

<div class="post-metadata">

**Author:** ![wrathjen](https://avatars.discourse-cdn.com/v4/letter/w/3bc359/32.png) [@wrathjen](https://discourse.crowdsec.net/u/wrathjen)\
**Post date:** [November 17, 2025, 8:47pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/9 "2025-11-17T20:47:08Z")

</div>

After deploying all the manual files and some tweaking for my specific setup (behind a CDN) it all looks to be working. Thank you.

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [November 18, 2025, 12:59pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/10 "2025-11-18T12:59:50Z")

</div>

Just a pre warning we will be changing how the remediation works when haproxy is behind a CDN so just ensure in future releases check the changelog.

the tldr; is using spoe groups means you can manually trigger the spoe protocol at certain times, this means we can not do the hacky req\_hdr\_ip function anymore and use the standard setting the src properly.

Glad it working though!

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [November 19, 2025, 12:16pm UTC](https://discourse.crowdsec.net/t/haproxy-sopa-bouncer-installation-failure/2715/11 "2025-11-19T12:16:12Z")

</div>

`0.2.0` is released which includes the lua and example files now.
