{"id":36606,"date":"2025-12-20T14:41:05","date_gmt":"2025-12-20T11:41:05","guid":{"rendered":"https:\/\/fatihsoysal.com\/blog\/?p=36606"},"modified":"2025-12-20T14:41:05","modified_gmt":"2025-12-20T11:41:05","slug":"haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme","status":"publish","type":"post","link":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/","title":{"rendered":"HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme"},"content":{"rendered":"<p><body><\/p>\n<h2>HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme<\/h2>\n<p>HAProxy, y\u00fcksek performansl\u0131 bir y\u00fck dengeleyici ve ters proxy olarak modern web altyap\u0131lar\u0131n\u0131n temel ta\u015flar\u0131ndan biridir. Uygulamalar\u0131n y\u00fcksek eri\u015filebilirlik, \u00f6l\u00e7eklenebilirlik ve performans gereksinimlerini kar\u015f\u0131lamak i\u00e7in tasarlanm\u0131\u015ft\u0131r. Ancak, g\u00fcn\u00fcm\u00fcz internet ortam\u0131nda sadece performans\u0131 art\u0131rmak yeterli de\u011fildir; g\u00fcvenlik de en az performans kadar kritik bir \u00f6neme sahiptir. Kullan\u0131c\u0131 verilerinin korunmas\u0131, veri b\u00fct\u00fcnl\u00fc\u011f\u00fcn\u00fcn sa\u011flanmas\u0131 ve yasal uyumluluk gereksinimleri, SSL\/TLS \u015fifrelemesinin vazge\u00e7ilmez olmas\u0131n\u0131 sa\u011flam\u0131\u015ft\u0131r. Let&#8217;s Encrypt, bu g\u00fcvenlik ihtiyac\u0131n\u0131 \u00fccretsiz, otomatik ve a\u00e7\u0131k bir sertifika yetkilisi olarak kar\u015f\u0131layarak, web sitelerinin HTTPS&#8217;ye ge\u00e7i\u015fini b\u00fcy\u00fck \u00f6l\u00e7\u00fcde kolayla\u015ft\u0131rm\u0131\u015ft\u0131r.<\/p>\n<p>Bu makale, Ubuntu 14.04 i\u015fletim sistemi \u00fczerinde \u00e7al\u0131\u015fan bir HAProxy kurulumunu Let&#8217;s Encrypt sertifikalar\u0131 ile nas\u0131l g\u00fcvenli hale getirece\u011finizi ad\u0131m ad\u0131m detayland\u0131rmaktad\u0131r. Ubuntu 14.04, eski bir s\u00fcr\u00fcm olmas\u0131na ra\u011fmen, baz\u0131 kurumsal veya \u00f6zel projelerde hala kullan\u0131l\u0131yor olabilir. Bu nedenle, bu platforma \u00f6zel kurulum ve yap\u0131land\u0131rma ad\u0131mlar\u0131n\u0131 ele almak, bu t\u00fcr sistemlerin modern g\u00fcvenlik standartlar\u0131na uygun hale getirilmesine yard\u0131mc\u0131 olacakt\u0131r. HAProxy&#8217;nin temel kurulumundan ba\u015flayarak, Let&#8217;s Encrypt sertifikalar\u0131n\u0131n al\u0131nmas\u0131, HAProxy&#8217;ye entegrasyonu ve otomatik yenileme s\u00fcre\u00e7leri detayl\u0131 bir \u015fekilde a\u00e7\u0131klanacakt\u0131r.<\/p>\n<h3>Giri\u015f<\/h3>\n<p>\u0130nternet trafi\u011finin b\u00fcy\u00fck bir k\u0131sm\u0131 art\u0131k \u015fifreli ba\u011flant\u0131lar \u00fczerinden ger\u00e7ekle\u015fmektedir. HTTPS (HTTP Secure), kullan\u0131c\u0131lar\u0131n taray\u0131c\u0131lar\u0131 ile web sunucular\u0131 aras\u0131ndaki ileti\u015fimi \u015fifreleyerek veri g\u00fcvenli\u011fini sa\u011flar. Bu \u015fifreleme, bir SSL\/TLS sertifikas\u0131 arac\u0131l\u0131\u011f\u0131yla ger\u00e7ekle\u015ftirilir. Geleneksel olarak, bu sertifikalar \u00fccretli ve manuel kurulum s\u00fcre\u00e7leri gerektiriyordu. Let&#8217;s Encrypt&#8217;in ortaya \u00e7\u0131k\u0131\u015f\u0131 ile bu durum de\u011fi\u015fti. Let&#8217;s Encrypt, herkesin alan adlar\u0131 i\u00e7in g\u00fcvenilir sertifikalar\u0131 \u00fccretsiz ve otomatik olarak almas\u0131n\u0131 sa\u011flayan bir sertifika yetkilisidir (CA). Bu, \u00f6zellikle k\u00fc\u00e7\u00fck ve orta \u00f6l\u00e7ekli i\u015fletmeler ile bireysel geli\u015ftiriciler i\u00e7in HTTPS&#8217;yi eri\u015filebilir hale getirmi\u015ftir.<\/p>\n<p>HAProxy, TCP ve HTTP tabanl\u0131 uygulamalar i\u00e7in y\u00fcksek eri\u015filebilirlik, y\u00fck dengeleme ve proxy \u00e7\u00f6z\u00fcmleri sunan a\u00e7\u0131k kaynakl\u0131 bir yaz\u0131l\u0131md\u0131r. Geli\u015fmi\u015f y\u00f6nlendirme kurallar\u0131, oturum kal\u0131c\u0131l\u0131\u011f\u0131, sa\u011fl\u0131k kontrolleri ve performans optimizasyonlar\u0131 sayesinde, karma\u015f\u0131k ve y\u00fcksek trafikli sistemlerde kritik bir rol oynar. HAProxy&#8217;nin kendisi bir web sunucusu olmamas\u0131na ra\u011fmen, gelen trafi\u011fi SSL\/TLS \u015fifrelemesi ile sonland\u0131r\u0131p (SSL Offloading), \u015fifresi \u00e7\u00f6z\u00fclm\u00fc\u015f trafi\u011fi arka u\u00e7 sunucular\u0131na iletebilir. Bu, arka u\u00e7 sunucular\u0131n\u0131n SSL\/TLS y\u00fck\u00fcn\u00fc hafifletir ve performanslar\u0131n\u0131 art\u0131r\u0131r.<\/p>\n<p>Ubuntu 14.04, LTS (Uzun S\u00fcreli Destek) bir s\u00fcr\u00fcm olmas\u0131na ra\u011fmen, 2019 y\u0131l\u0131nda standart deste\u011fi sona ermi\u015ftir. Ancak baz\u0131 eski sistemler veya \u00f6zel uygulamalar nedeniyle hala kullan\u0131l\u0131yor olabilir. Bu makale, bu t\u00fcr bir ortamda HAProxy ve Let&#8217;s Encrypt entegrasyonunu ele alarak, g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131 kapatmaya ve modern \u015fifreleme standartlar\u0131n\u0131 uygulamaya yard\u0131mc\u0131 olacakt\u0131r.<\/p>\n<h3>\u00d6n Gereksinimler<\/h3>\n<p>Bu makaledeki ad\u0131mlar\u0131 ba\u015far\u0131yla uygulayabilmek i\u00e7in a\u015fa\u011f\u0131daki \u00f6n gereksinimlere sahip olman\u0131z gerekmektedir:<\/p>\n<p>*   <strong>Ubuntu 14.04 Sunucusu:<\/strong> Root eri\u015fimi veya <code>sudo<\/code> yetkilerine sahip bir Ubuntu 14.04 i\u015fletim sistemine sahip bir sunucu.<br \/>\n*   <strong>HAProxy Kurulumu:<\/strong> Sunucunuzda HAProxy&#8217;nin kurulu ve temel olarak yap\u0131land\u0131r\u0131lm\u0131\u015f olmas\u0131. E\u011fer kurulu de\u011filse, kurulum ad\u0131mlar\u0131 makalede k\u0131saca belirtilecektir.<br \/>\n*   <strong>Alan Ad\u0131:<\/strong> HAProxy&#8217;yi g\u00fcvenli hale getirmek istedi\u011finiz bir alan ad\u0131 (\u00f6rne\u011fin, <code>ornekalanadi.com<\/code>). Bu alan ad\u0131n\u0131n DNS kay\u0131tlar\u0131 (A veya AAAA kay\u0131tlar\u0131) sunucunuzun genel IP adresine i\u015faret etmelidir. Let&#8217;s Encrypt sertifikalar\u0131 yaln\u0131zca ger\u00e7ek, do\u011frulanabilir alan adlar\u0131 i\u00e7in verilir.<br \/>\n*   <strong>G\u00fcvenlik Duvar\u0131 Ayarlar\u0131:<\/strong> Sunucunuzun g\u00fcvenlik duvar\u0131nda (UFW, iptables vb.) 80 (HTTP) ve 443 (HTTPS) portlar\u0131n\u0131n d\u0131\u015far\u0131dan eri\u015fime a\u00e7\u0131k olmas\u0131 gerekmektedir. Let&#8217;s Encrypt, alan ad\u0131 do\u011frulamas\u0131 i\u00e7in 80 numaral\u0131 portu kullanabilir ve HTTPS trafi\u011fi i\u00e7in 443 numaral\u0131 portun a\u00e7\u0131k olmas\u0131 zorunludur.<br \/>\n*   <strong>Temel Linux Bilgisi:<\/strong> Komut sat\u0131r\u0131 kullan\u0131m\u0131, dosya d\u00fczenleme ve servis y\u00f6netimi gibi temel Linux komutlar\u0131 hakk\u0131nda bilgi sahibi olmak.<\/p>\n<h3>HAProxy Kurulumu ve Temel Yap\u0131land\u0131rma<\/h3>\n<p>E\u011fer HAProxy sunucunuzda kurulu de\u011filse, a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izleyerek kurabilirsiniz. Ubuntu 14.04&#8217;\u00fcn varsay\u0131lan depolar\u0131 genellikle HAProxy 1.5 s\u00fcr\u00fcm\u00fcn\u00fc i\u00e7erir. Daha yeni \u00f6zellikler (\u00f6rne\u011fin HTTP\/2 veya TLS 1.3 deste\u011fi) i\u00e7in daha g\u00fcncel bir s\u00fcr\u00fcm gerekebilir, ancak bu makalede temel SSL\/TLS yap\u0131land\u0131rmas\u0131 i\u00e7in 1.5 s\u00fcr\u00fcm\u00fc yeterlidir.<\/p>\n<h4>HAProxy Kurulumu<\/h4>\n<p>Paket listesini g\u00fcncelleyin ve HAProxy&#8217;yi kurun:<\/p>\n<pre><code class=\"language-bash\">sudo apt-get update\nsudo apt-get install haproxy<\/code><\/pre>\n<p>Kurulum tamamland\u0131ktan sonra, HAProxy servisinin durumunu kontrol edebilirsiniz:<\/p>\n<pre><code class=\"language-bash\">sudo service haproxy status<\/code><\/pre>\n<p>E\u011fer servis \u00e7al\u0131\u015fm\u0131yorsa, ba\u015flat\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo service haproxy start<\/code><\/pre>\n<p>HAProxy&#8217;nin sistem ba\u015flang\u0131c\u0131nda otomatik olarak ba\u015flamas\u0131n\u0131 sa\u011flamak i\u00e7in:<\/p>\n<pre><code class=\"language-bash\">sudo update-rc.d haproxy enable<\/code><\/pre>\n<h4>Temel HTTP Y\u00fck Dengeleme Yap\u0131land\u0131rmas\u0131<\/h4>\n<p>HAProxy&#8217;nin ana yap\u0131land\u0131rma dosyas\u0131 <code>\/etc\/haproxy\/haproxy.cfg<\/code> konumundad\u0131r. Bu dosyay\u0131 d\u00fczenlemeden \u00f6nce bir yede\u011fini almak iyi bir uygulamad\u0131r:<\/p>\n<pre><code class=\"language-bash\">sudo cp \/etc\/haproxy\/haproxy.cfg \/etc\/haproxy\/haproxy.cfg.bak<\/code><\/pre>\n<p>\u015eimdi, dosyay\u0131 bir metin d\u00fczenleyici ile a\u00e7\u0131n (\u00f6rne\u011fin <code>nano<\/code>):<\/p>\n<pre><code class=\"language-bash\">sudo nano \/etc\/haproxy\/haproxy.cfg<\/code><\/pre>\n<p>Varsay\u0131lan yap\u0131land\u0131rma dosyas\u0131n\u0131n i\u00e7eri\u011fini temizleyip, basit bir HTTP y\u00fck dengeleme yap\u0131land\u0131rmas\u0131 ile ba\u015flayabiliriz. A\u015fa\u011f\u0131daki \u00f6rnek, gelen HTTP trafi\u011fini iki adet arka u\u00e7 web sunucusuna (\u00f6rne\u011fin Nginx veya Apache) y\u00f6nlendiren temel bir yap\u0131land\u0131rmay\u0131 g\u00f6stermektedir:<\/p>\n<pre><code class=\"language-haproxy\">global\n    log \/dev\/log    local0 notice\n    chroot \/var\/lib\/haproxy\n    user haproxy\n    group haproxy\n    daemon\n    stats socket \/run\/haproxy\/admin.sock mode 660 level admin\n    stats timeout 30s\n\ndefaults\n    log     global\n    mode    http\n    option  httplog\n    option  dontlognull\n    timeout connect 5000ms\n    timeout client  50000ms\n    timeout server  50000ms\n    errorfile 400 \/etc\/haproxy\/errors\/400.http\n    errorfile 403 \/etc\/haproxy\/errors\/403.http\n    errorfile 408 \/etc\/haproxy\/errors\/408.http\n    errorfile 500 \/etc\/haproxy\/errors\/500.http\n    errorfile 502 \/etc\/haproxy\/errors\/502.http\n    errorfile 503 \/etc\/haproxy\/errors\/503.http\n    errorfile 504 \/etc\/haproxy\/errors\/504.http\n\nfrontend http_in\n    bind *:80\n    default_backend web_servers\n\nbackend web_servers\n    balance roundrobin\n    server web1 192.168.1.10:80 check\n    server web2 192.168.1.11:80 check<\/code><\/pre>\n<p>Yukar\u0131daki yap\u0131land\u0131rmay\u0131 a\u00e7\u0131klayal\u0131m:<\/p>\n<p>*   <strong><code>global<\/code>:<\/strong> HAProxy&#8217;nin genel ayarlar\u0131n\u0131 i\u00e7erir. Loglama, kullan\u0131c\u0131\/grup ayarlar\u0131 ve istatistik soketi gibi ayarlar burada tan\u0131mlan\u0131r.<br \/>\n*   <strong><code>defaults<\/code>:<\/strong> <code>frontend<\/code> ve <code>backend<\/code> b\u00f6l\u00fcmleri i\u00e7in varsay\u0131lan ayarlar\u0131 belirler. <code>mode http<\/code> HTTP trafi\u011fi i\u00e7in, <code>timeout<\/code> de\u011ferleri ba\u011flant\u0131 s\u00fcrelerini kontrol eder.<br \/>\n<em>   <strong><code>frontend http_in<\/code>:<\/strong> Gelen HTTP (80 portu) trafi\u011fini dinleyen b\u00f6l\u00fcmd\u00fcr. <code>bind <\/em>:80<\/code> t\u00fcm IP adresleri \u00fczerinden 80 numaral\u0131 portu dinler. <code>default_backend web_servers<\/code> gelen t\u00fcm trafi\u011fi <code>web_servers<\/code> adl\u0131 arka uca y\u00f6nlendirir.<br \/>\n*   <strong><code>backend web_servers<\/code>:<\/strong> Ger\u00e7ek web sunucular\u0131n\u0131 tan\u0131mlar. <code>balance roundrobin<\/code> gelen istekleri s\u0131rayla sunuculara da\u011f\u0131t\u0131r. <code>server web1 192.168.1.10:80 check<\/code> ve <code>server web2 192.168.1.11:80 check<\/code> \u00f6rnek arka u\u00e7 sunucular\u0131d\u0131r. <code>check<\/code> parametresi sa\u011fl\u0131k kontrol\u00fc yap\u0131lmas\u0131n\u0131 sa\u011flar. Bu IP adreslerini kendi arka u\u00e7 sunucular\u0131n\u0131z\u0131n IP adresleri ile de\u011fi\u015ftirmeniz gerekmektedir.<\/p>\n<p>Yap\u0131land\u0131rmay\u0131 kaydettikten sonra, HAProxy yap\u0131land\u0131rma dosyas\u0131n\u0131n s\u00f6zdizimini kontrol edin:<\/p>\n<pre><code class=\"language-bash\">sudo haproxy -c -f \/etc\/haproxy\/haproxy.cfg<\/code><\/pre>\n<p>E\u011fer <code>Configuration file is valid<\/code> mesaj\u0131n\u0131 g\u00f6r\u00fcrseniz, HAProxy servisini yeniden ba\u015flatabilirsiniz:<\/p>\n<pre><code class=\"language-bash\">sudo service haproxy restart<\/code><\/pre>\n<p>Bu noktada, <code>http:\/\/ornekalanadi.com<\/code> adresine eri\u015fmeye \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131zda, HAProxy&#8217;nin arka u\u00e7 sunucular\u0131n\u0131zdan birine trafik y\u00f6nlendirmesi gerekmektedir.<\/p>\n<h3>Let&#8217;s Encrypt ve Certbot Kurulumu<\/h3>\n<p>Let&#8217;s Encrypt sertifikalar\u0131n\u0131 almak ve y\u00f6netmek i\u00e7in genellikle Certbot arac\u0131 kullan\u0131l\u0131r. Certbot, ACME (Automated Certificate Management Environment) protokol\u00fcn\u00fc uygulayan ve sertifika al\u0131m\u0131n\u0131, kurulumunu ve yenilemesini otomatikle\u015ftiren bir istemcidir. Ubuntu 14.04 i\u00e7in Certbot&#8217;un kurulumu, resmi PPA (Personal Package Archive) kullan\u0131larak ger\u00e7ekle\u015ftirilir.<\/p>\n<h4>Certbot Kurulumu<\/h4>\n<p>Certbot&#8217;u kurmak i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izleyin:<\/p>\n<p>1.  Certbot PPA&#8217;s\u0131n\u0131 sisteminize ekleyin:<\/p>\n<pre><code class=\"language-bash\">sudo apt-get install software-properties-common\n    sudo add-apt-repository ppa:certbot\/certbot<\/code><\/pre>\n<p>    <code>add-apt-repository<\/code> komutu bulunamazsa, <code>python-software-properties<\/code> paketini kurman\u0131z gerekebilir:<\/p>\n<pre><code class=\"language-bash\">sudo apt-get install python-software-properties<\/code><\/pre>\n<p>2.  Paket listesini g\u00fcncelleyin:<\/p>\n<pre><code class=\"language-bash\">sudo apt-get update<\/code><\/pre>\n<p>3.  Certbot&#8217;u kurun:<\/p>\n<pre><code class=\"language-bash\">sudo apt-get install certbot<\/code><\/pre>\n<p>Certbot art\u0131k sisteminizde y\u00fckl\u00fcd\u00fcr.<\/p>\n<h4>Let&#8217;s Encrypt Sertifikas\u0131 Alma<\/h4>\n<p>HAProxy, Certbot ile do\u011frudan bir entegrasyon eklentisine sahip de\u011fildir (Nginx veya Apache gibi). Bu nedenle, sertifika almak i\u00e7in <code>certonly<\/code> komutunu ve <code>--standalone<\/code> veya <code>--webroot<\/code> do\u011frulama y\u00f6ntemlerini kullanmam\u0131z gerekecektir.<\/p>\n<p>*   <strong><code>--standalone<\/code> y\u00f6ntemi:<\/strong> Certbot, sertifika al\u0131m\u0131 s\u0131ras\u0131nda ge\u00e7ici olarak kendi web sunucusunu 80 numaral\u0131 portta \u00e7al\u0131\u015ft\u0131r\u0131r. Bu, HAProxy&#8217;nin 80 numaral\u0131 portu serbest b\u0131rakmas\u0131n\u0131 gerektirdi\u011finden, k\u0131sa bir kesinti ya\u015fan\u0131r. \u0130lk sertifika al\u0131m\u0131 i\u00e7in genellikle en basit y\u00f6ntemdir.<br \/>\n*   <strong><code>--webroot<\/code> y\u00f6ntemi:<\/strong> Certbot, belirtilen bir dizine do\u011frulama dosyalar\u0131n\u0131 yerle\u015ftirir ve bu dosyalar\u0131n HTTP \u00fczerinden eri\u015filebilir olmas\u0131n\u0131 bekler. Bu y\u00f6ntem, HAProxy&#8217;nin 80 numaral\u0131 portu dinlemeye devam etmesini sa\u011flar, ancak <code>.well-known\/acme-challenge<\/code> isteklerini bu dizini sunan bir arka u\u00e7 sunucusuna (\u00f6rne\u011fin Nginx veya Apache) y\u00f6nlendirmek veya Certbot&#8217;un kendi web sunucusunu bu dizini sunacak \u015fekilde yap\u0131land\u0131rmak gerekir. HAProxy&#8217;nin tek ba\u015f\u0131na \u00e7al\u0131\u015ft\u0131\u011f\u0131 bir senaryoda bu daha karma\u015f\u0131k olabilir.<\/p>\n<p>Bu makalede, ilk sertifika al\u0131m\u0131 i\u00e7in <code>--standalone<\/code> y\u00f6ntemini kullanaca\u011f\u0131z, \u00e7\u00fcnk\u00fc bu, HAProxy&#8217;nin tek ba\u015f\u0131na \u00e7al\u0131\u015ft\u0131\u011f\u0131 bir ortamda en kolay ba\u015flang\u0131\u00e7t\u0131r. Otomatik yenileme b\u00f6l\u00fcm\u00fcnde ise kesintisiz yenileme i\u00e7in <code>--standalone<\/code> y\u00f6ntemini <code>pre-hook<\/code> ve <code>post-hook<\/code> ile otomatikle\u015ftirece\u011fiz.<\/p>\n<h5>Sertifika Al\u0131m\u0131 (Standalone Y\u00f6ntemi)<\/h5>\n<p>1.  <strong>HAProxy&#8217;yi durdurun:<\/strong> Certbot&#8217;un kendi web sunucusunu 80 numaral\u0131 portta \u00e7al\u0131\u015ft\u0131rabilmesi i\u00e7in HAProxy&#8217;nin 80 numaral\u0131 portu serbest b\u0131rakmas\u0131 gerekir.<\/p>\n<pre><code class=\"language-bash\">sudo service haproxy stop<\/code><\/pre>\n<p>2.  <strong>Sertifikay\u0131 al\u0131n:<\/strong> <code>certbot certonly --standalone -d yourdomain.com -d www.yourdomain.com<\/code> komutunu \u00e7al\u0131\u015ft\u0131r\u0131n. <code>yourdomain.com<\/code> ve <code>www.yourdomain.com<\/code> yerine kendi alan adlar\u0131n\u0131z\u0131 yaz\u0131n. Birden fazla alan ad\u0131 i\u00e7in <code>-d<\/code> parametresini tekrar kullanabilirsiniz.<\/p>\n<pre><code class=\"language-bash\">sudo certbot certonly --standalone -d ornekalanadi.com -d www.ornekalanadi.com<\/code><\/pre>\n<p>    Certbot sizden e-posta adresinizi girmenizi ve Let&#8217;s Encrypt hizmet \u015fartlar\u0131n\u0131 kabul etmenizi isteyecektir. Ba\u015far\u0131l\u0131 olursa, sertifika dosyalar\u0131n\u0131z <code>\/etc\/letsencrypt\/live\/ornekalanadi.com\/<\/code> dizininde olu\u015fturulacakt\u0131r.<\/p>\n<p>3.  <strong>HAProxy&#8217;yi ba\u015flat\u0131n:<\/strong> Sertifikalar al\u0131nd\u0131ktan sonra HAProxy&#8217;yi tekrar ba\u015flat\u0131n.<\/p>\n<pre><code class=\"language-bash\">sudo service haproxy start<\/code><\/pre>\n<h5>HAProxy \u0130\u00e7in Sertifika Dosyalar\u0131n\u0131 Haz\u0131rlama<\/h5>\n<p>HAProxy, SSL\/TLS sertifikas\u0131n\u0131 ve \u00f6zel anahtar\u0131 tek bir PEM format\u0131nda dosya olarak bekler. Let&#8217;s Encrypt, bu dosyalar\u0131 ayr\u0131 ayr\u0131 sa\u011flar (<code>fullchain.pem<\/code> ve <code>privkey.pem<\/code>). Bu iki dosyay\u0131 birle\u015ftirmeniz gerekmektedir.<\/p>\n<p>1.  HAProxy sertifikalar\u0131 i\u00e7in bir dizin olu\u015fturun:<\/p>\n<pre><code class=\"language-bash\">sudo mkdir -p \/etc\/haproxy\/certs<\/code><\/pre>\n<p>2.  Sertifika ve \u00f6zel anahtar\u0131 birle\u015ftirin:<\/p>\n<pre><code class=\"language-bash\">sudo cat \/etc\/letsencrypt\/live\/ornekalanadi.com\/fullchain.pem \/etc\/letsencrypt\/live\/ornekalanadi.com\/privkey.pem | sudo tee \/etc\/haproxy\/certs\/ornekalanadi.com.pem<\/code><\/pre>\n<p>    Bu komut, <code>fullchain.pem<\/code> (sertifika zinciri) ve <code>privkey.pem<\/code> (\u00f6zel anahtar) dosyalar\u0131n\u0131 birle\u015ftirerek <code>\/etc\/haproxy\/certs\/ornekalanadi.com.pem<\/code> adl\u0131 yeni bir dosya olu\u015fturur.<\/p>\n<p>3.  Dosya izinlerini ayarlay\u0131n: \u00d6zel anahtar i\u00e7eren bu dosyan\u0131n sadece root kullan\u0131c\u0131s\u0131 taraf\u0131ndan okunabilir olmas\u0131 \u00f6nemlidir.<\/p>\n<pre><code class=\"language-bash\">sudo chmod -R go-rwx \/etc\/haproxy\/certs<\/code><\/pre>\n<p>Art\u0131k HAProxy i\u00e7in SSL\/TLS sertifika dosyan\u0131z haz\u0131r.<\/p>\n<h3>HAProxy&#8217;yi SSL\/TLS ile Yap\u0131land\u0131rma<\/h3>\n<p>\u015eimdi HAProxy yap\u0131land\u0131rma dosyas\u0131n\u0131 (<code>\/etc\/haproxy\/haproxy.cfg<\/code>) Let&#8217;s Encrypt sertifikalar\u0131n\u0131 kullanacak \u015fekilde d\u00fczenlememiz gerekiyor. Bu, 443 numaral\u0131 portu dinleyen yeni bir <code>frontend<\/code> tan\u0131mlamay\u0131 ve HTTP trafi\u011fini HTTPS&#8217;ye y\u00f6nlendirmeyi i\u00e7erecektir.<\/p>\n<p>1.  HAProxy yap\u0131land\u0131rma dosyas\u0131n\u0131 a\u00e7\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo nano \/etc\/haproxy\/haproxy.cfg<\/code><\/pre>\n<p>2.  Mevcut <code>frontend http_in<\/code> b\u00f6l\u00fcm\u00fcn\u00fc HTTP&#8217;den HTTPS&#8217;ye y\u00f6nlendirme yapacak \u015fekilde g\u00fcncelleyin ve yeni bir <code>frontend https_in<\/code> b\u00f6l\u00fcm\u00fc ekleyin:<\/p>\n<pre><code class=\"language-haproxy\">global\n        log \/dev\/log    local0 notice\n        chroot \/var\/lib\/haproxy\n        user haproxy\n        group haproxy\n        daemon\n        stats socket \/run\/haproxy\/admin.sock mode 660 level admin\n        stats timeout 30s\n\n    defaults\n        log     global\n        mode    http\n        option  httplog\n        option  dontlognull\n        timeout connect 5000ms\n        timeout client  50000ms\n        timeout server  50000ms\n        errorfile 400 \/etc\/haproxy\/errors\/400.http\n        errorfile 403 \/etc\/haproxy\/errors\/403.http\n        errorfile 408 \/etc\/haproxy\/errors\/408.http\n        errorfile 500 \/etc\/haproxy\/errors\/500.http\n        errorfile 502 \/etc\/haproxy\/errors\/502.http\n        errorfile 503 \/etc\/haproxy\/errors\/503.http\n        errorfile 504 \/etc\/haproxy\/errors\/504.http\n\n    # HTTP (80 portu) trafi\u011fini HTTPS'ye y\u00f6nlendirme\n    frontend http_in\n        bind *:80\n        redirect scheme https code 301 if !{ ssl_fc }\n\n    # HTTPS (443 portu) trafi\u011fi\n    frontend https_in\n        bind *:443 ssl crt \/etc\/haproxy\/certs\/ornekalanadi.com.pem\n        # SSL\/TLS g\u00fcvenlik ayarlar\u0131\n        ssl-default-bind-ciphers ECDHE+AESGCM:ECDHE+CHACHA20:DHE+AESGCM:DHE+CHACHA20:ECDHE+AES256:DHE+AES256:ECDHE+AES128:DHE+AES128:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4:!HMAC_SHA1:!SHA1:!DHE-RSA-AES256-SHA:!DHE-RSA-AES128-SHA:!DHE-RSA-CAMELLIA256-SHA:!DHE-RSA-CAMELLIA128-SHA\n        ssl-default-bind-options no-sslv3 no-tlsv10 no-tlsv11\n        # HSTS (Strict-Transport-Security) ba\u015fl\u0131\u011f\u0131 ekleme\n        rspadd  Strict-Transport-Security:\\ max-age=15768000\n        default_backend web_servers\n\n    backend web_servers\n        balance roundrobin\n        server web1 192.168.1.10:80 check\n        server web2 192.168.1.11:80 check<\/code><\/pre>\n<p>Yap\u0131land\u0131rmadaki \u00f6nemli de\u011fi\u015fiklikler:<\/p>\n<p>*   <strong><code>frontend http_in<\/code>:<\/strong><br \/>\n    <em>   <code>bind <\/em>:80<\/code> ile 80 numaral\u0131 portu dinlemeye devam eder.<br \/>\n    *   <code>redirect scheme https code 301 if !{ ssl_fc }<\/code> kural\u0131, SSL\/TLS ile \u015fifrelenmemi\u015f (yani HTTP) gelen t\u00fcm istekleri kal\u0131c\u0131 olarak (301 kodu ile) HTTPS&#8217;ye y\u00f6nlendirir.<br \/>\n*   <strong><code>frontend https_in<\/code>:<\/strong><br \/>\n    <em>   <code>bind <\/em>:443 ssl crt \/etc\/haproxy\/certs\/ornekalanadi.com.pem<\/code> ile 443 numaral\u0131 portu dinler. <code>ssl<\/code> parametresi SSL\/TLS sonland\u0131rmay\u0131 etkinle\u015ftirir ve <code>crt<\/code> parametresi sertifika dosyas\u0131n\u0131n yolunu belirtir.<br \/>\n    *   <code>ssl-default-bind-ciphers<\/code> ve <code>ssl-default-bind-options<\/code>: G\u00fcvenli \u015fifreleme s\u00fcitlerini ve TLS protokol s\u00fcr\u00fcmlerini (\u00f6rne\u011fin TLS 1.2&#8217;yi zorlamak i\u00e7in SSLv3, TLSv1.0, TLSv1.1&#8217;i devre d\u0131\u015f\u0131 b\u0131rakma) yap\u0131land\u0131r\u0131r. Bu ayarlar, bilinen g\u00fcvenlik a\u00e7\u0131klar\u0131na kar\u015f\u0131 koruma sa\u011flar ve daha g\u00fc\u00e7l\u00fc \u015fifrelemeyi te\u015fvik eder. Ubuntu 14.04&#8217;teki HAProxy 1.5 s\u00fcr\u00fcm\u00fc genellikle TLS 1.2&#8217;yi destekler, ancak TLS 1.3 deste\u011fi i\u00e7in daha yeni bir HAProxy s\u00fcr\u00fcm\u00fc (1.9+) gerekebilir.<br \/>\n    *   <code>rspadd Strict-Transport-Security:\\ max-age=15768000<\/code>: HSTS (HTTP Strict Transport Security) ba\u015fl\u0131\u011f\u0131n\u0131 ekler. Bu ba\u015fl\u0131k, taray\u0131c\u0131lara belirli bir s\u00fcre boyunca (burada 6 ay) alan ad\u0131n\u0131za her zaman HTTPS \u00fczerinden eri\u015fmeleri gerekti\u011fini bildirir. Bu, man-in-the-middle sald\u0131r\u0131lar\u0131na kar\u015f\u0131 ek koruma sa\u011flar.<\/p>\n<p>Yap\u0131land\u0131rmay\u0131 kaydettikten sonra, HAProxy yap\u0131land\u0131rma dosyas\u0131n\u0131n s\u00f6zdizimini tekrar kontrol edin:<\/p>\n<pre><code class=\"language-bash\">sudo haproxy -c -f \/etc\/haproxy\/haproxy.cfg<\/code><\/pre>\n<p>E\u011fer ge\u00e7erliyse, HAProxy servisini yeniden ba\u015flat\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo service haproxy restart<\/code><\/pre>\n<p>\u015eimdi taray\u0131c\u0131n\u0131zdan <code>http:\/\/ornekalanadi.com<\/code> adresine gidin. Otomatik olarak <code>https:\/\/ornekalanadi.com<\/code> adresine y\u00f6nlendirilmeniz ve ba\u011flant\u0131n\u0131n g\u00fcvenli (ye\u015fil kilit simgesi) oldu\u011funu g\u00f6rmeniz gerekir.<\/p>\n<h3>Sertifika Otomatik Yenileme<\/h3>\n<p>Let&#8217;s Encrypt sertifikalar\u0131 90 g\u00fcn boyunca ge\u00e7erlidir. Bu nedenle, sertifikalar\u0131n s\u00fcresi dolmadan \u00f6nce d\u00fczenli olarak yenilenmesi gerekir. Certbot, bu yenileme i\u015flemini otomatikle\u015ftirmek i\u00e7in <code>renew<\/code> komutunu sa\u011flar.<\/p>\n<h4>Yenileme Komutu<\/h4>\n<p>Certbot&#8217;u yenileme modunda \u00e7al\u0131\u015ft\u0131rmak i\u00e7in basit\u00e7e \u015funu kullan\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo certbot renew<\/code><\/pre>\n<p>Bu komut, s\u00fcresi dolmak \u00fczere olan t\u00fcm sertifikalar\u0131 kontrol eder ve uygun olanlar\u0131 yeniler. Varsay\u0131lan olarak, sertifikalar s\u00fcresi dolmas\u0131na 30 g\u00fcnden az kald\u0131\u011f\u0131nda yenilenir.<\/p>\n<p>HAProxy&#8217;nin 80 numaral\u0131 portu dinledi\u011fi bir ortamda, <code>certbot renew<\/code> komutu yine <code>--standalone<\/code> do\u011frulama y\u00f6ntemini kullanmaya \u00e7al\u0131\u015f\u0131r ve bu da HAProxy&#8217;nin durdurulmas\u0131n\u0131 gerektirir. Bunu otomatikle\u015ftirmek i\u00e7in <code>cron<\/code> i\u015fi ile <code>pre-hook<\/code> ve <code>post-hook<\/code> se\u00e7eneklerini kullanabiliriz.<\/p>\n<h4>Cron \u0130\u015fi ile Otomatik Yenileme<\/h4>\n<p>Sertifikalar\u0131n otomatik olarak yenilenmesi i\u00e7in bir <code>cron<\/code> i\u015fi ayarlamak en iyi y\u00f6ntemdir. Bu <code>cron<\/code> i\u015fi, Certbot&#8217;u d\u00fczenli aral\u0131klarla \u00e7al\u0131\u015ft\u0131racak ve yenileme ba\u015far\u0131l\u0131 olursa HAProxy&#8217;yi yeniden ba\u015flatacakt\u0131r.<\/p>\n<p>1.  Cron tablounuzu d\u00fczenlemek i\u00e7in:<\/p>\n<pre><code class=\"language-bash\">sudo crontab -e<\/code><\/pre>\n<p>2.  A\u015fa\u011f\u0131daki sat\u0131r\u0131 dosyan\u0131n sonuna ekleyin:<\/p>\n<pre><code class=\"language-cron\">0 <em>\/12 <\/em> <em> <\/em> \/usr\/bin\/certbot renew --quiet --pre-hook \"service haproxy stop\" --post-hook \"service haproxy start\"<\/code><\/pre>\n<p>    Bu sat\u0131r\u0131 a\u00e7\u0131klayal\u0131m:<br \/>\n    <em>   <code>0 <\/em>\/12 <em> <\/em> *<\/code>: Cron zamanlamas\u0131d\u0131r. Her 12 saatte bir (yani g\u00fcnde iki kez) \u00e7al\u0131\u015f\u0131r. Bu, sertifikalar\u0131n s\u00fcresi dolmadan \u00f6nce yenilenmesi i\u00e7in yeterli bir s\u0131kl\u0131kt\u0131r.<br \/>\n    *   <code>\/usr\/bin\/certbot renew<\/code>: Certbot&#8217;un yenileme komutunu \u00e7al\u0131\u015ft\u0131r\u0131r.<br \/>\n    *   <code>--quiet<\/code>: Sadece hatalar veya \u00f6nemli olaylar oldu\u011funda \u00e7\u0131kt\u0131 verir.<br \/>\n    *   <code>--pre-hook \"service haproxy stop\"<\/code>: Certbot yenilemeye ba\u015flamadan hemen \u00f6nce HAProxy servisini durdurur. Bu, Certbot&#8217;un 80 numaral\u0131 portu kullanmas\u0131na izin verir.<br \/>\n    *   <code>--post-hook \"service haproxy start\"<\/code>: Certbot yenilemeyi tamamlad\u0131ktan sonra HAProxy servisini ba\u015flat\u0131r.<br \/>\n    *   <strong>\u00d6nemli Not:<\/strong> Certbot&#8217;un <code>--post-hook<\/code> sonras\u0131 HAProxy&#8217;nin yeniden ba\u015flat\u0131lmas\u0131, yeni sertifika dosyas\u0131n\u0131n HAProxy taraf\u0131ndan y\u00fcklenmesini sa\u011flar. Ancak, yeni sertifika dosyas\u0131 <code>\/etc\/letsencrypt\/live\/ornekalanadi.com\/<\/code> konumunda olu\u015ftu\u011funda, HAProxy&#8217;nin bekledi\u011fi birle\u015ftirilmi\u015f PEM dosyas\u0131n\u0131 (<code>\/etc\/haproxy\/certs\/ornekalanadi.com.pem<\/code>) g\u00fcncellememiz gerekir. Bu ad\u0131m\u0131 <code>post-hook<\/code> i\u00e7inde yapmal\u0131y\u0131z.<\/p>\n<p>    G\u00fcncellenmi\u015f cron i\u015fi a\u015fa\u011f\u0131daki gibi olmal\u0131d\u0131r:<\/p>\n<pre><code class=\"language-cron\">0 <em>\/12 <\/em> <em> <\/em> \/usr\/bin\/certbot renew --quiet --pre-hook \"service haproxy stop\" --post-hook \"cat \/etc\/letsencrypt\/live\/ornekalanadi.com\/fullchain.pem \/etc\/letsencrypt\/live\/ornekalanadi.com\/privkey.pem > \/etc\/haproxy\/certs\/ornekalanadi.com.pem && service haproxy start\"<\/code><\/pre>\n<p>    Bu <code>post-hook<\/code> komutu, yeni sertifikalar\u0131 birle\u015ftirir ve ard\u0131ndan HAProxy&#8217;yi ba\u015flat\u0131r.<br \/>\n    <strong>Dikkat:<\/strong> Cron i\u015fi <code>root<\/code> kullan\u0131c\u0131s\u0131 alt\u0131nda \u00e7al\u0131\u015ft\u0131\u011f\u0131 i\u00e7in <code>sudo<\/code> komutlar\u0131na gerek yoktur.<\/p>\n<p>3.  Dosyay\u0131 kaydedin ve kapat\u0131n. Cron i\u015fi otomatik olarak etkinle\u015fecektir.<\/p>\n<h4>Yenileme Testi<\/h4>\n<p>Yenileme i\u015flemini ger\u00e7ekten \u00e7al\u0131\u015ft\u0131rmadan test etmek i\u00e7in <code>dry-run<\/code> parametresini kullanabilirsiniz:<\/p>\n<pre><code class=\"language-bash\">sudo certbot renew --dry-run<\/code><\/pre>\n<p>Bu komut, sertifikalar\u0131n yenilenip yenilenemeyece\u011fini kontrol eder, ancak ger\u00e7ek bir yenileme yapmaz. Herhangi bir sorun olup olmad\u0131\u011f\u0131n\u0131 anlamak i\u00e7in iyi bir y\u00f6ntemdir.<\/p>\n<h3>Ek G\u00fcvenlik \u00d6nlemleri ve En \u0130yi Uygulamalar<\/h3>\n<p>HAProxy ve Let&#8217;s Encrypt entegrasyonunu tamamlad\u0131ktan sonra, sisteminizin genel g\u00fcvenli\u011fini art\u0131rmak i\u00e7in ek ad\u0131mlar atman\u0131z \u00f6nemlidir.<\/p>\n<h4>G\u00fcvenlik Duvar\u0131 Yap\u0131land\u0131rmas\u0131<\/h4>\n<p>Sadece gerekli portlar\u0131n (80 ve 443) d\u0131\u015far\u0131dan eri\u015fime a\u00e7\u0131k oldu\u011fundan emin olun. Di\u011fer t\u00fcm portlar\u0131 kapatmak, sald\u0131r\u0131 y\u00fczeyini azalt\u0131r. Ubuntu&#8217;da UFW (Uncomplicated Firewall) kullanabilirsiniz:<\/p>\n<pre><code class=\"language-bash\">sudo ufw allow 80\/tcp\nsudo ufw allow 443\/tcp\nsudo ufw allow ssh # SSH eri\u015fimi i\u00e7in\nsudo ufw enable\nsudo ufw status<\/code><\/pre>\n<h4>HAProxy S\u00fcr\u00fcm Y\u00f6netimi<\/h4>\n<p>Ubuntu 14.04&#8217;\u00fcn varsay\u0131lan depolar\u0131ndaki HAProxy s\u00fcr\u00fcm\u00fc (genellikle 1.5.x) eski olabilir. Daha yeni g\u00fcvenlik yamalar\u0131, performans iyile\u015ftirmeleri ve \u00f6zellikler (\u00f6rne\u011fin HTTP\/2, TLS 1.3 deste\u011fi) i\u00e7in daha g\u00fcncel bir HAProxy s\u00fcr\u00fcm\u00fcne y\u00fckseltmek isteyebilirsiniz. Bunun i\u00e7in HAProxy&#8217;nin resmi PPA&#8217;s\u0131n\u0131 veya derleme y\u00f6ntemini kullanabilirsiniz. Ancak bu, Ubuntu 14.04 gibi eski bir sistemde ek ba\u011f\u0131ml\u0131l\u0131k sorunlar\u0131na yol a\u00e7abilir ve dikkatli bir \u015fekilde test edilmelidir.<\/p>\n<h4>Loglama ve \u0130zleme<\/h4>\n<p>HAProxy loglar\u0131n\u0131 d\u00fczenli olarak kontrol etmek, olas\u0131 g\u00fcvenlik ihlallerini veya performans sorunlar\u0131n\u0131 tespit etmek i\u00e7in kritik \u00f6neme sahiptir. HAProxy loglar\u0131n\u0131 <code>syslog<\/code> \u00fczerinden merkezi bir loglama sunucusuna g\u00f6ndermek veya bir izleme arac\u0131 (\u00f6rne\u011fin Prometheus, ELK Stack) ile entegre etmek iyi bir uygulamad\u0131r.<\/p>\n<p>HAProxy yap\u0131land\u0131rman\u0131zdaki <code>global<\/code> b\u00f6l\u00fcm\u00fcnde log ayarlar\u0131n\u0131 kontrol edin:<\/p>\n<pre><code class=\"language-haproxy\">global\n    log \/dev\/log    local0 notice\n    # ...<\/code><\/pre>\n<p>Bu ayar, HAProxy loglar\u0131n\u0131 <code>syslog<\/code>&#8216;a g\u00f6nderir. Loglar genellikle <code>\/var\/log\/syslog<\/code> veya <code>\/var\/log\/haproxy.log<\/code> (rsyslog yap\u0131land\u0131rmas\u0131na ba\u011fl\u0131 olarak) adresinde bulunabilir.<\/p>\n<h4>DDoS Korumas\u0131<\/h4>\n<p>HAProxy, temel DDoS koruma yeteneklerine sahiptir. <code>stick-table<\/code> ve <code>rate-limit<\/code> gibi \u00f6zellikler kullanarak belirli IP adreslerinden gelen a\u015f\u0131r\u0131 istekleri s\u0131n\u0131rlayabilir veya engelleyebilirsiniz.<\/p>\n<p>\u00d6rnek bir rate limiting yap\u0131land\u0131rmas\u0131:<\/p>\n<pre><code class=\"language-haproxy\">frontend https_in\n    # ... di\u011fer ayarlar ...\n    acl abuse src_http_req_rate(mylimit) ge 100\n    http-request deny if abuse\n    stick-table type ip size 1m expire 30s store http_req_rate(10s) name mylimit\n    # ...<\/code><\/pre>\n<p>Bu \u00f6rnek, bir IP adresinden 10 saniye i\u00e7inde 100&#8217;den fazla istek geldi\u011finde bu IP&#8217;den gelen istekleri engeller.<\/p>\n<h4>HTTP\/2 ve TLS 1.3<\/h4>\n<p>HAProxy 1.8 ve \u00fczeri s\u00fcr\u00fcmler HTTP\/2 deste\u011fi sunarken, TLS 1.3 deste\u011fi HAProxy 1.9 ve \u00fczeri s\u00fcr\u00fcmlerde mevcuttur. Ubuntu 14.04&#8217;teki HAProxy 1.5.x s\u00fcr\u00fcm\u00fc bu \u00f6zellikleri do\u011frudan desteklemeyebilir. E\u011fer bu \u00f6zelliklere ihtiyac\u0131n\u0131z varsa, daha yeni bir HAProxy s\u00fcr\u00fcm\u00fcne y\u00fckseltme yapman\u0131z veya daha g\u00fcncel bir i\u015fletim sistemi kullanman\u0131z gerekebilir.<\/p>\n<h4>G\u00fcvenlik Ba\u015fl\u0131klar\u0131<\/h4>\n<p>HSTS&#8217;ye ek olarak, di\u011fer g\u00fcvenlik ba\u015fl\u0131klar\u0131n\u0131 da (\u00f6rne\u011fin <code>X-Frame-Options<\/code>, <code>X-Content-Type-Options<\/code>, <code>Content-Security-Policy<\/code>) HAProxy \u00fczerinden ekleyebilirsiniz. Bu ba\u015fl\u0131klar, \u00e7e\u015fitli taray\u0131c\u0131 tabanl\u0131 sald\u0131r\u0131lara kar\u015f\u0131 ek koruma sa\u011flar.<\/p>\n<p>\u00d6rnek olarak <code>X-Frame-Options<\/code> ba\u015fl\u0131\u011f\u0131n\u0131 eklemek:<\/p>\n<pre><code class=\"language-haproxy\">frontend https_in\n    # ...\n    rspadd X-Frame-Options:\\ SAMEORIGIN\n    # ...<\/code><\/pre>\n<h3>Sorun Giderme<\/h3>\n<p>Kurulum veya yap\u0131land\u0131rma s\u0131ras\u0131nda kar\u015f\u0131la\u015fabilece\u011finiz yayg\u0131n sorunlar ve \u00e7\u00f6z\u00fcmleri:<\/p>\n<h4>HAProxy Yap\u0131land\u0131rma Hatalar\u0131<\/h4>\n<p>*   <strong>Belirti:<\/strong> HAProxy servisi ba\u015flat\u0131lam\u0131yor veya yeniden ba\u015flat\u0131lam\u0131yor.<br \/>\n*   <strong>\u00c7\u00f6z\u00fcm:<\/strong> HAProxy yap\u0131land\u0131rma dosyas\u0131n\u0131n s\u00f6zdizimini kontrol edin:<\/p>\n<pre><code class=\"language-bash\">sudo haproxy -c -f \/etc\/haproxy\/haproxy.cfg<\/code><\/pre>\n<p>    Hata mesajlar\u0131n\u0131 dikkatlice okuyun ve belirtilen sat\u0131rlardaki sorunlar\u0131 d\u00fczeltin. Log dosyalar\u0131n\u0131 (<code>\/var\/log\/syslog<\/code> veya <code>\/var\/log\/haproxy.log<\/code>) kontrol etmek de yard\u0131mc\u0131 olabilir.<\/p>\n<h4>Certbot Hatalar\u0131<\/h4>\n<p>*   <strong>Belirti:<\/strong> Sertifika al\u0131m\u0131 ba\u015far\u0131s\u0131z oluyor.<br \/>\n*   <strong>\u00c7\u00f6z\u00fcm:<\/strong><br \/>\n    *   <strong>Port 80 me\u015fgul hatas\u0131:<\/strong> Certbot&#8217;un <code>--standalone<\/code> modunda \u00e7al\u0131\u015fabilmesi i\u00e7in 80 numaral\u0131 portun bo\u015f olmas\u0131 gerekir. HAProxy veya ba\u015fka bir web sunucusunun durduruldu\u011fundan emin olun.<br \/>\n    *   <strong>DNS sorunlar\u0131:<\/strong> Alan ad\u0131n\u0131z\u0131n DNS kay\u0131tlar\u0131n\u0131n do\u011fru bir \u015fekilde sunucunuzun IP adresine i\u015faret etti\u011finden emin olun. <code>dig yourdomain.com<\/code> komutu ile kontrol edebilirsiniz.<br \/>\n    *   <strong>G\u00fcvenlik duvar\u0131:<\/strong> 80 ve 443 portlar\u0131n\u0131n a\u00e7\u0131k oldu\u011fundan emin olun.<br \/>\n    *   Certbot loglar\u0131n\u0131 kontrol edin: <code>\/var\/log\/letsencrypt\/<\/code> dizinindeki log dosyalar\u0131 detayl\u0131 hata mesajlar\u0131 i\u00e7erir.<\/p>\n<h4>HTTPS Ba\u011flant\u0131 Sorunlar\u0131<\/h4>\n<p>*   <strong>Belirti:<\/strong> Taray\u0131c\u0131da &#8220;Ba\u011flant\u0131n\u0131z g\u00fcvenli de\u011fil&#8221; hatas\u0131 veya sertifika ge\u00e7ersiz uyar\u0131s\u0131.<br \/>\n*   <strong>\u00c7\u00f6z\u00fcm:<\/strong><br \/>\n    *   <strong>Sertifika yolu hatas\u0131:<\/strong> HAProxy yap\u0131land\u0131rmas\u0131nda <code>crt<\/code> parametresinin do\u011fru sertifika dosya yolunu g\u00f6sterdi\u011finden emin olun.<br \/>\n    *   <strong>PEM dosyas\u0131 birle\u015ftirme:<\/strong> <code>fullchain.pem<\/code> ve <code>privkey.pem<\/code> dosyalar\u0131n\u0131 do\u011fru s\u0131rayla birle\u015ftirdi\u011finizden emin olun.<br \/>\n    *   <strong>Sertifika s\u00fcresi:<\/strong> Sertifikan\u0131n s\u00fcresinin dolup dolmad\u0131\u011f\u0131n\u0131 kontrol edin.<br \/>\n    *   <strong>SSL\/TLS ayarlar\u0131:<\/strong> <code>ssl-default-bind-ciphers<\/code> ve <code>ssl-default-bind-options<\/code> ayarlar\u0131n\u0131n \u00e7ok k\u0131s\u0131tlay\u0131c\u0131 olup olmad\u0131\u011f\u0131n\u0131 veya eski taray\u0131c\u0131larla uyumsuzluk yarat\u0131p yaratmad\u0131\u011f\u0131n\u0131 kontrol edin. SSL Labs gibi ara\u00e7larla sertifika ve TLS yap\u0131land\u0131rman\u0131z\u0131 test edebilirsiniz.<br \/>\n    *   <strong>G\u00fcvenlik duvar\u0131:<\/strong> 443 portunun a\u00e7\u0131k oldu\u011fundan emin olun.<\/p>\n<h3>Sonu\u00e7<\/h3>\n<p>Bu makalede, Ubuntu 14.04 \u00fczerinde HAProxy&#8217;yi Let&#8217;s Encrypt sertifikalar\u0131 ile g\u00fcvenli hale getirme s\u00fcrecini ad\u0131m ad\u0131m ele ald\u0131k. HAProxy&#8217;nin temel kurulumundan ba\u015flayarak, Certbot arac\u0131l\u0131\u011f\u0131yla Let&#8217;s Encrypt sertifikalar\u0131n\u0131n nas\u0131l al\u0131naca\u011f\u0131n\u0131, bu sertifikalar\u0131n HAProxy&#8217;ye nas\u0131l entegre edilece\u011fini ve son olarak otomatik yenileme s\u00fcrecini nas\u0131l yap\u0131land\u0131raca\u011f\u0131m\u0131z\u0131 \u00f6\u011frendik. Ayr\u0131ca, sistemin genel g\u00fcvenli\u011fini art\u0131rmak i\u00e7in ek \u00f6nlemler ve s\u0131k kar\u015f\u0131la\u015f\u0131lan sorunlar\u0131n giderme y\u00f6ntemleri hakk\u0131nda bilgi verdik.<\/p>\n<p>HAProxy ve Let&#8217;s Encrypt kombinasyonu, y\u00fcksek performansl\u0131 ve g\u00fcvenli bir web altyap\u0131s\u0131 olu\u015fturmak i\u00e7in g\u00fc\u00e7l\u00fc bir \u00e7\u00f6z\u00fcmd\u00fcr. Let&#8217;s Encrypt&#8217;in sundu\u011fu \u00fccretsiz ve otomatik sertifikalar sayesinde, SSL\/TLS \u015fifrelemesi art\u0131k her web sitesi i\u00e7in eri\u015filebilir hale gelmi\u015ftir. HAProxy ise bu \u015fifrelemeyi verimli bir \u015fekilde sonland\u0131rarak arka u\u00e7 sunucular\u0131n\u0131n y\u00fck\u00fcn\u00fc hafifletir ve uygulamalar\u0131n performans\u0131n\u0131 art\u0131r\u0131r.<\/p>\n<p>Ubuntu 14.04 gibi eski bir i\u015fletim sistemi \u00fczerinde \u00e7al\u0131\u015fmak, baz\u0131 k\u0131s\u0131tlamalar\u0131 (\u00f6rne\u011fin eski HAProxy veya Certbot s\u00fcr\u00fcmleri) beraberinde getirse de, bu makaledeki ad\u0131mlar sayesinde sisteminizi modern g\u00fcvenlik standartlar\u0131na uygun hale getirebilirsiniz. Ancak uzun vadede, daha g\u00fcncel i\u015fletim sistemlerine ve yaz\u0131l\u0131m s\u00fcr\u00fcmlerine ge\u00e7i\u015f yapmak, en yeni g\u00fcvenlik yamalar\u0131ndan ve performans iyile\u015ftirmelerinden faydalanmak ad\u0131na \u015fiddetle tavsiye edilir.<\/p>\n<p>Bu entegrasyon, uygulaman\u0131z\u0131n g\u00fcvenli\u011fini art\u0131rmakla kalmayacak, ayn\u0131 zamanda arama motoru s\u0131ralamalar\u0131nda HTTPS&#8217;nin bir fakt\u00f6r olmas\u0131 nedeniyle SEO performans\u0131n\u0131za da olumlu katk\u0131 sa\u011flayacakt\u0131r. Unutmay\u0131n, g\u00fcvenlik s\u00fcrekli bir s\u00fcre\u00e7tir ve sistemlerinizi d\u00fczenli olarak g\u00fcncel tutmak, loglar\u0131 izlemek ve en iyi uygulamalar\u0131 takip etmek hayati \u00f6neme sahiptir.<\/body><\/p>\n","protected":false},"excerpt":{"rendered":"HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme\nHAProxy, y\u00fcksek performansl\u0131 bir y\u00fck dengeleyici ve ters proxy olarak mo","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_page_header_type":"","csco_page_load_nextpost":"","csco_page_subscribe_form":"","csco_page_contact_form":"","footnotes":""},"categories":[1468],"tags":[],"class_list":{"0":"post-36606","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-ubuntu","7":"cs-entry","8":"cs-video-wrap"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.5 (Yoast SEO v25.3.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>HAProxy&#039;yi Ubuntu 14.04 \u00dczerinde Let&#039;s Encrypt ile G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\" \/>\n<meta property=\"og:locale\" content=\"tr_TR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HAProxy&#039;yi Ubuntu 14.04 \u00dczerinde Let&#039;s Encrypt ile G\u00fcvenli Hale Getirme\" \/>\n<meta property=\"og:description\" content=\"HAProxy&#039;yi Ubuntu 14.04 \u00dczerinde Let&#039;s Encrypt ile G\u00fcvenli Hale Getirme HAProxy, y\u00fcksek performansl\u0131 bir y\u00fck dengeleyici ve ters proxy olarak mo\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\" \/>\n<meta property=\"og:site_name\" content=\"Kodlar\u0131n Gizemli D\u00fcnyas\u0131\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-20T11:41:05+00:00\" \/>\n<meta name=\"author\" content=\"Fatih Soysal\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Yazan:\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fatih Soysal\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tahmini okuma s\u00fcresi\" \/>\n\t<meta name=\"twitter:data2\" content=\"20 dakika\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\"},\"author\":{\"name\":\"Fatih Soysal\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"headline\":\"HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme\",\"datePublished\":\"2025-12-20T11:41:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\"},\"wordCount\":3300,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"articleSection\":[\"Ubuntu\"],\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\",\"name\":\"HAProxy'yi Ubuntu 14.04 \u00dczerinde Let's Encrypt ile G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131\",\"isPartOf\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#website\"},\"datePublished\":\"2025-12-20T11:41:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#breadcrumb\"},\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Anasayfa\",\"item\":\"https:\/\/fatihsoysal.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#website\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/\",\"name\":\"Fatihsoysal.com\",\"description\":\"Blog - Yaz\u0131l\u0131m D\u00fcnyas\u0131 Tecr\u00fcbelerim\",\"publisher\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fatihsoysal.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"tr\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\",\"name\":\"Fatih Soysal\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"tr\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png\",\"contentUrl\":\"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png\",\"width\":512,\"height\":512,\"caption\":\"Fatih Soysal\"},\"logo\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"Kullan\u0131m ve kodlama m\u00fckemmeliyetini odak alan uygulamalar olu\u015fturma deneyimine sahip, profesyonel olarak 15+ y\u0131l \u00fczeri deneyime sahip bir yaz\u0131l\u0131m m\u00fchendisi.\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/author\/fatihsoysal\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"HAProxy'yi Ubuntu 14.04 \u00dczerinde Let's Encrypt ile G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/","og_locale":"tr_TR","og_type":"article","og_title":"HAProxy'yi Ubuntu 14.04 \u00dczerinde Let's Encrypt ile G\u00fcvenli Hale Getirme","og_description":"HAProxy'yi Ubuntu 14.04 \u00dczerinde Let's Encrypt ile G\u00fcvenli Hale Getirme HAProxy, y\u00fcksek performansl\u0131 bir y\u00fck dengeleyici ve ters proxy olarak mo","og_url":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/","og_site_name":"Kodlar\u0131n Gizemli D\u00fcnyas\u0131","article_published_time":"2025-12-20T11:41:05+00:00","author":"Fatih Soysal","twitter_card":"summary_large_image","twitter_misc":{"Yazan:":"Fatih Soysal","Tahmini okuma s\u00fcresi":"20 dakika"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#article","isPartOf":{"@id":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/"},"author":{"name":"Fatih Soysal","@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"headline":"HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme","datePublished":"2025-12-20T11:41:05+00:00","mainEntityOfPage":{"@id":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/"},"wordCount":3300,"commentCount":0,"publisher":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"articleSection":["Ubuntu"],"inLanguage":"tr","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/fatihsoysal.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/","url":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/","name":"HAProxy'yi Ubuntu 14.04 \u00dczerinde Let's Encrypt ile G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131","isPartOf":{"@id":"https:\/\/fatihsoysal.com\/blog\/#website"},"datePublished":"2025-12-20T11:41:05+00:00","breadcrumb":{"@id":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#breadcrumb"},"inLanguage":"tr","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/fatihsoysal.com\/blog\/haproxyyi-ubuntu-14-04-uzerinde-lets-encrypt-ile-guvenli-hale-getirme\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Anasayfa","item":"https:\/\/fatihsoysal.com\/blog\/"},{"@type":"ListItem","position":2,"name":"HAProxy&#8217;yi Ubuntu 14.04 \u00dczerinde Let&#8217;s Encrypt ile G\u00fcvenli Hale Getirme"}]},{"@type":"WebSite","@id":"https:\/\/fatihsoysal.com\/blog\/#website","url":"https:\/\/fatihsoysal.com\/blog\/","name":"Fatihsoysal.com","description":"Blog - Yaz\u0131l\u0131m D\u00fcnyas\u0131 Tecr\u00fcbelerim","publisher":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fatihsoysal.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"tr"},{"@type":["Person","Organization"],"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1","name":"Fatih Soysal","image":{"@type":"ImageObject","inLanguage":"tr","@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png","contentUrl":"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png","width":512,"height":512,"caption":"Fatih Soysal"},"logo":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/"},"description":"Kullan\u0131m ve kodlama m\u00fckemmeliyetini odak alan uygulamalar olu\u015fturma deneyimine sahip, profesyonel olarak 15+ y\u0131l \u00fczeri deneyime sahip bir yaz\u0131l\u0131m m\u00fchendisi.","url":"https:\/\/fatihsoysal.com\/blog\/author\/fatihsoysal\/"}]}},"yoast_meta":{"yoast_wpseo_title":"","yoast_wpseo_metadesc":"","yoast_wpseo_canonical":""},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/36606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/comments?post=36606"}],"version-history":[{"count":1,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/36606\/revisions"}],"predecessor-version":[{"id":36607,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/36606\/revisions\/36607"}],"wp:attachment":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/media?parent=36606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/categories?post=36606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/tags?post=36606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}