---
title: Charmhub | Deploy HAProxy using Charmhub - The Open Operator Collection
description: Deploy the latest version of HAProxy on any cloud.
url: https://charmhub.io/haproxy/libraries/spoe_auth
---

# HAProxy

[haproxy-team](https://charmhub.io/publisher/haproxy-team "View all packages from haproxy-team")

* [haproxy-team](https://charmhub.io/publisher/haproxy-team "View all packages from haproxy-team")
* [Networking](https://charmhub.io/?filter=networking)

Platform:

24.04

22.04

20.04

18.04

16.04

14.04

stable 147

```
juju deploy haproxy
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/haproxy/libraries/spoe_auth#drawer)

## charms.haproxy.v0.spoe\_auth

* [*Docstrings*Docstrings](https://charmhub.io/haproxy/libraries/spoe_auth)
  [*Code*Source code](https://charmhub.io/haproxy/libraries/spoe_auth/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.haproxy.v0.spoe_auth
    ```

    [Download spoe\_auth.py](https://charmhub.io/haproxy/libraries/spoe_auth/download)
  + *Last updated* 11 Aug 2026
  + *Revision* Library version 0.3

SPOE-auth interface library.

##### Getting Started

To get started using the library, you need to first declare the library in
the charm-libs section of your `charmcraft.yaml` file:

```
charm-libs:
- lib: haproxy.spoe_auth
  version: "0"
```

Then, fetch the library using `charmcraft`:

```
cd some-charm
charmcraft fetch-libs
```

##### Using the library as the Provider

The provider charm should expose the interface as shown below:

```
provides:
    spoe-auth:
        interface: spoe-auth
        limit: 1
```

Then, to initialise the library:

```
from charms.haproxy.v0.spoe_auth import SpoeAuthProvider, HaproxyEvent

class SpoeAuthCharm(CharmBase):
    def __init__(self, *args):
        super().__init__(*args)
        self.spoe_auth = SpoeAuthProvider(self, relation_name="spoe-auth")

        self.framework.observe(
            self.on.config_changed, self._on_config_changed
        )

    def _on_config_changed(self, event):
        # Publish the SPOE auth configuration
        self.spoe_auth.provide_spoe_auth_requirements(
            spop_port=8081,
            oidc_callback_port=5000,
            event=HaproxyEvent.ON_HTTP_REQUEST,
            var_authenticated_scope="sess",
            var_authenticated="is_authenticated",
            var_redirect_url_scope="sess",
            var_redirect_url="redirect_url",
            cookie_name="auth_session",
            hostname="auth.example.com",
            oidc_callback_path="/oauth2/callback",
        )
```

---

Index

* [def value\_contains\_invalid\_characters(
  value
  )](https://charmhub.io/haproxy/libraries/spoe_auth#value_contains_invalid_characters)
* [def validate\_hostname(
  value
  )](https://charmhub.io/haproxy/libraries/spoe_auth#validate_hostname)
* [class DataValidationError](https://charmhub.io/haproxy/libraries/spoe_auth#datavalidationerror)
* [class SpoeAuthInvalidRelationDataError](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthinvalidrelationdataerror)
* [class HaproxyEvent](https://charmhub.io/haproxy/libraries/spoe_auth#haproxyevent)
* [class SpoeAuthProviderAppData](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthproviderappdata)
* [class SpoeAuthProviderUnitData](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthproviderunitdata)
* [class SpoeAuthProvider](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthprovider)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthprovider-__init__)
* + [def relations(
    self)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthprovider-relations)
* + [def provide\_spoe\_auth\_requirements(
    self,
    relation,
    spop\_port,
    oidc\_callback\_port,
    event,
    message\_name,
    var\_authenticated\_scope,
    var\_authenticated,
    var\_redirect\_url\_scope,
    var\_redirect\_url,
    cookie\_name,
    hostname,
    oidc\_callback\_path,
    unit\_address)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthprovider-provide_spoe_auth_requirements)
* [class SpoeAuthAvailableEvent](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthavailableevent)
* [class SpoeAuthRemovedEvent](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthremovedevent)
* [class SpoeAuthRequirer](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-__init__)
* + [def relation(
    self)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-relation)
* + [def relations(
    self)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-relations)
* + [def is\_available(
    self)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-is_available)
* + [def get\_data(
    self)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-get_data)
* + [def get\_provider\_unit\_data(
    self,
    relation)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-get_provider_unit_data)
* + [def get\_provider\_application\_data(
    self,
    relation)](https://charmhub.io/haproxy/libraries/spoe_auth#spoeauthrequirer-get_provider_application_data)

#### def value\_contains\_invalid\_characters(value: str)

Validate if value contains invalid haproxy config characters.

Arguments

value

The value to validate.

Returns

The validated value.

#### def validate\_hostname(value: str)

Validate if value is a valid hostname per RFC 1123.

Arguments

value

The value to validate.

Returns

The validated value.

#### class DataValidationError

Description

Raised when data validation fails. None

#### class SpoeAuthInvalidRelationDataError

Description

Raised when data validation of the spoe-auth relation fails. None

#### class HaproxyEvent

Enumeration of HAProxy SPOE events.

Attributes

ON\_FRONTEND\_HTTP\_REQUEST

Event triggered on frontend HTTP request.

#### class SpoeAuthProviderAppData

Configuration model for SPOE authentication provider.

Attributes

spop\_port

The port on the agent listening for SPOP.

oidc\_callback\_port

The port on the agent handling OIDC callbacks.

event

The event that triggers SPOE messages (e.g., on-http-request).

var\_authenticated\_scope

Scope of the variable set by the SPOE agent for auth status.

var\_authenticated

Name of the variable set by the SPOE agent for auth status.

var\_redirect\_url\_scope

Scope of the variable set by the SPOE agent for IDP redirect URL.

var\_redirect\_url

Name of the variable set by the SPOE agent for IDP redirect URL.

cookie\_name

Name of the authentication cookie used by the SPOE agent.

oidc\_callback\_path

Path for OIDC callback.

oidc\_callback\_hostname

The hostname HAProxy should route OIDC callbacks to.

#### class SpoeAuthProviderUnitData

spoe-auth provider unit data.

Attributes

address

IP address of the unit.

#### class SpoeAuthProvider

SPOE auth interface provider implementation.

Attributes

relations

Related applications.

Methods

SpoeAuthProvider.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

Initialize the SpoeAuthProvider.

Arguments

charm

The charm that is instantiating the library.

relation\_name

The name of the relation to bind to.

SpoeAuthProvider.
relations(

*self*
)

The list of Relation instances associated with this relation\_name.

Returns

list[Relation]

The list of relations.

SpoeAuthProvider.
provide\_spoe\_auth\_requirements(

*self*

,
relation: Relation

,
spop\_port: int

,
oidc\_callback\_port: int

,
event: HaproxyEvent

,
message\_name: str

,
var\_authenticated\_scope: str

,
var\_authenticated: str

,
var\_redirect\_url\_scope: str

,
var\_redirect\_url: str

,
cookie\_name: str

,
hostname: str

,
oidc\_callback\_path: str

,
unit\_address
)

Set the SPOE auth configuration in the application databag.

Arguments

relation

The relation instance to set data on.

spop\_port

The port on the agent listening for SPOP.

oidc\_callback\_port

The port on the agent handling OIDC callbacks.

event

The event that triggers SPOE messages.

message\_name

The name of the SPOE message that the provider expects.

var\_authenticated\_scope

Scope of the variable for auth status.

var\_authenticated

Name of the variable for auth status.

var\_redirect\_url\_scope

Scope of the variable for IDP redirect URL.

var\_redirect\_url

Name of the variable for IDP redirect URL.

cookie\_name

Name of the authentication cookie.

hostname

The hostname HAProxy should route OIDC callbacks to.

oidc\_callback\_path

Path for OIDC callback.

unit\_address

The address of the unit.

#### class SpoeAuthAvailableEvent

Description

SpoeAuthAvailableEvent custom event. None

#### class SpoeAuthRemovedEvent

Description

SpoeAuthRemovedEvent custom event. None

#### class SpoeAuthRequirer

SPOE auth interface requirer implementation.

Attributes

on

Custom events of the requirer.

relation

The related application.

Methods

SpoeAuthRequirer.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

Initialize the SpoeAuthRequirer.

Arguments

charm

The charm that is instantiating the library.

relation\_name

The name of the relation to bind to.

SpoeAuthRequirer.
relation(

*self*
)

The relation instance associated with this relation\_name.

Returns

Optional[Relation]

The relation instance, or None if not available.

SpoeAuthRequirer.
relations(

*self*
)

The list of relations associated with this relation\_name.

Returns

The list of relations.

SpoeAuthRequirer.
is\_available(

*self*
)

Check if the SPOE auth configuration is available and valid.

Returns

bool

True if configuration is available and valid, False otherwise.

SpoeAuthRequirer.
get\_data(

*self*
)

Get the SPOE auth configuration from the provider.

Returns

Optional[SpoeAuthProviderAppData]

The SPOE auth configuration,
or None if not available.

SpoeAuthRequirer.
get\_provider\_unit\_data(

*self*

,
relation: Relation
)

Fetch and validate the requirer's units data.

Arguments

relation

The relation to fetch unit data from.

Returns

list[SpoeAuthProviderUnitData]

List of validated unit data from the provider.

SpoeAuthRequirer.
get\_provider\_application\_data(

*self*

,
relation: Relation
)

Fetch and validate the requirer's application databag.

Arguments

relation

The relation to fetch application data from.

Returns

RequirerApplicationData

Validated application data from the requirer.
