---
title: Charmhub | Deploy Squid Reverseproxy using Charmhub - The Open Operator Collection
description: Deploy the latest version of Squid Reverseproxy on any cloud.
url: https://charmhub.io/squid-reverseproxy/configurations
---

# Squid Reverseproxy

[Squid Reverse Proxy Charmers](https://charmhub.io/publisher/squid-reverseproxy-charmers "View all packages from Squid Reverse Proxy Charmers")

* [Squid Reverse Proxy Charmers](https://charmhub.io/publisher/squid-reverseproxy-charmers "View all packages from Squid Reverse Proxy Charmers")
* [Networking](https://charmhub.io/?filter=networking)

Platform:

22.04

20.04

18.04

16.04

14.04

stable 25

```
juju deploy squid-reverseproxy
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [auth\_list](https://charmhub.io/squid-reverseproxy/configurations#auth_list)
* [avg\_obj\_size\_kb](https://charmhub.io/squid-reverseproxy/configurations#avg_obj_size_kb)
* [cache\_dir](https://charmhub.io/squid-reverseproxy/configurations#cache_dir)
* [cache\_mem\_mb](https://charmhub.io/squid-reverseproxy/configurations#cache_mem_mb)
* [cache\_size\_mb](https://charmhub.io/squid-reverseproxy/configurations#cache_size_mb)
* [continue\_retrieve\_on\_abort](https://charmhub.io/squid-reverseproxy/configurations#continue_retrieve_on_abort)
* [dns\_v4\_first](https://charmhub.io/squid-reverseproxy/configurations#dns_v4_first)
* [enable\_forward\_proxy](https://charmhub.io/squid-reverseproxy/configurations#enable_forward_proxy)
* [enable\_https](https://charmhub.io/squid-reverseproxy/configurations#enable_https)
* [force\_https](https://charmhub.io/squid-reverseproxy/configurations#force_https)
* [https\_options](https://charmhub.io/squid-reverseproxy/configurations#https_options)
* [https\_port](https://charmhub.io/squid-reverseproxy/configurations#https_port)
* [log\_format](https://charmhub.io/squid-reverseproxy/configurations#log_format)
* [log\_hosts\_allow](https://charmhub.io/squid-reverseproxy/configurations#log_hosts_allow)
* [max\_obj\_size\_in\_mem\_kb](https://charmhub.io/squid-reverseproxy/configurations#max_obj_size_in_mem_kb)
* [max\_obj\_size\_kb](https://charmhub.io/squid-reverseproxy/configurations#max_obj_size_kb)
* [metrics](https://charmhub.io/squid-reverseproxy/configurations#metrics)
* [metrics\_sample\_interval](https://charmhub.io/squid-reverseproxy/configurations#metrics_sample_interval)
* [metrics\_scheme](https://charmhub.io/squid-reverseproxy/configurations#metrics_scheme)
* [metrics\_target](https://charmhub.io/squid-reverseproxy/configurations#metrics_target)
* [nagios\_check\_http\_params](https://charmhub.io/squid-reverseproxy/configurations#nagios_check_http_params)
* [nagios\_check\_https\_params](https://charmhub.io/squid-reverseproxy/configurations#nagios_check_https_params)
* [nagios\_context](https://charmhub.io/squid-reverseproxy/configurations#nagios_context)
* [nagios\_down\_threshold](https://charmhub.io/squid-reverseproxy/configurations#nagios_down_threshold)
* [nagios\_service\_type](https://charmhub.io/squid-reverseproxy/configurations#nagios_service_type)
* [nagios\_servicegroups](https://charmhub.io/squid-reverseproxy/configurations#nagios_servicegroups)
* [package\_status](https://charmhub.io/squid-reverseproxy/configurations#package_status)
* [port](https://charmhub.io/squid-reverseproxy/configurations#port)
* [port\_options](https://charmhub.io/squid-reverseproxy/configurations#port_options)
* [refresh\_patterns](https://charmhub.io/squid-reverseproxy/configurations#refresh_patterns)
* [services](https://charmhub.io/squid-reverseproxy/configurations#services)
* [services\_only\_from\_config](https://charmhub.io/squid-reverseproxy/configurations#services_only_from_config)
* [snmp\_allowed\_ips](https://charmhub.io/squid-reverseproxy/configurations#snmp_allowed_ips)
* [snmp\_community](https://charmhub.io/squid-reverseproxy/configurations#snmp_community)
* [snmp\_port](https://charmhub.io/squid-reverseproxy/configurations#snmp_port)
* [ssl\_cert](https://charmhub.io/squid-reverseproxy/configurations#ssl_cert)
* [ssl\_certfile](https://charmhub.io/squid-reverseproxy/configurations#ssl_certfile)
* [ssl\_cipher\_suite](https://charmhub.io/squid-reverseproxy/configurations#ssl_cipher_suite)
* [ssl\_key](https://charmhub.io/squid-reverseproxy/configurations#ssl_key)
* [ssl\_keyfile](https://charmhub.io/squid-reverseproxy/configurations#ssl_keyfile)
* [ssl\_options](https://charmhub.io/squid-reverseproxy/configurations#ssl_options)
* [target\_objs\_per\_dir](https://charmhub.io/squid-reverseproxy/configurations#target_objs_per_dir)
* [upstream\_proxy\_address](https://charmhub.io/squid-reverseproxy/configurations#upstream_proxy_address)
* [upstream\_proxy\_options](https://charmhub.io/squid-reverseproxy/configurations#upstream_proxy_options)
* [upstream\_proxy\_port](https://charmhub.io/squid-reverseproxy/configurations#upstream_proxy_port)
* [via](https://charmhub.io/squid-reverseproxy/configurations#via)
* [wait\_for\_auth\_helper](https://charmhub.io/squid-reverseproxy/configurations#wait_for_auth_helper)
* [x\_balancer\_name\_allowed](https://charmhub.io/squid-reverseproxy/configurations#x_balancer_name_allowed)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* auth\_list | string

  YAML-formatted list of squid auth dictionaries. For example:
  auth\_list: |

  + dstdomain: [www.ubuntu.com]
    src:
    - 1.2.3.4
    - 5.6.7.0/24
  + "!port": [80]
    http\_access: deny
  + url\_regex: ["https?://[^/]+[.]internal(/.\*)?"]
    src: [192.168.0.0/16]

  You can use the following command to verify your YAML list, passed on stdin:

  python3 -c 'import sys, yaml; print(yaml.dump(yaml.safe\_load(sys.stdin.read())))'
* avg\_obj\_size\_kb | int

  Default: 16

  Estimated average size of a cached object.
* cache\_dir | string

  The top-level directory where cache swap files will be stored.
* cache\_mem\_mb | int

  Default: 256

  Maximum size of in-memory object cache (MB). Should be smaller than cache\_size\_mb. Set to zero to disable caching completely.
* cache\_size\_mb | int

  Default: 512

  Maximum size of the on-disk object cache (MB). Set to zero to disable disk caching.
* continue\_retrieve\_on\_abort | boolean

  Always continue if they are being cached when the request is aborted
* dns\_v4\_first | boolean

  If true, prefer IPv4 addresses for dual-stack sites.
* enable\_forward\_proxy | boolean

  Enables forward proxying
* enable\_https | boolean

  Enable https access for squid, requires a squid compiled with --enable-ssl, certificate and private key
* force\_https | boolean

  Force HTTPS connections with a 301 redirect from HTTP. Requires "enable\_https".
* https\_options | string

  Default: accel vhost

  Options for https port
* https\_port | int

  Default: 443

  Squid https listening port
* log\_format | string

  Default: %>a %ui %un [%tl] "%rm %ru HTTP/%rv" %>Hs %<st "%{Referer}>h" "%{User-Agent}>h" %Ss:%Sh

  Format of the squid log.
* log\_hosts\_allow | string

  Hosts that should be allowed to rsync logs. This will only work if the
  nrpe charm is related to this one. If possible, use something like
  filebeat to ship out logs to an observability stack instead.
* max\_obj\_size\_in\_mem\_kb | int

  Default: 512

  Maximum size of an object to be cached in memory (KB).
* max\_obj\_size\_kb | int

  Default: 8192

  Maximum size of an object to be cached (KB).
* metrics | string

  Default: cacheCpuUsage
  cacheCurrentSwapSize
  cacheDnsSvcTime.5
  cacheHttpErrors
  cacheHttpAllSvcTime.5
  cacheHttpHitSvcTime.5
  cacheHttpMissSvcTime.5
  cacheHttpNhSvcTime.5
  cacheHttpNmSvcTime.5
  cacheHttpInKb
  cacheHttpOutKb
  cacheMaxResSize
  cacheMemMaxSize
  cacheMemUsage
  cacheNumObjCount
  cachePeerRtt
  cacheRequestByteRatio.5
  cacheRequestHitRatio.5
  cacheSwapHighWM
  cacheSwapLowWM
  cacheSwapMaxSize
  cacheSysNumReads
  cacheSysPageFaults
  cacheSysStorage
  cacheSysVMsize

  List of SNMP metrics to be exported. Names should match Squid's SNMP names at http://wiki.squid-cache.org/Features/Snmp#Squid\_OIDs. By default, this charm uses the 5min sampling when averages are used and specifies the .5 measurements explicitly. If you want to use 1m or 60m timings, you should be explicit (.1/.60, and probably change the cron job frequency. Warning: any metric starting with 'cachePeer...' will produce 1 metric per configured peer, so can increase the number of metrics rapidly if you have lots of peers.
* metrics\_sample\_interval | int

  Default: 5

  Period for metrics cron job to run in minutes
* metrics\_scheme | string

  Default: dev.$UNIT.squid.$METRIC

  Naming scheme for metrics. Special values $UNIT and $METRIC can be used
  for more complex schemes, e.g. for suffixes for graphite processing .
* metrics\_target | string

  Destination for metrics, format "host:port". If not present and valid, metrics disabled.
* nagios\_check\_http\_params | string

  The parameters to pass to the nrpe plugin check\_http. String will be formatted with config data
* nagios\_check\_https\_params | string

  The parameters to pass to the nrpe plugin check\_http. String will be formatted with config data
* nagios\_context | string

  Default: juju

  Used by the nrpe-external-master subordinate charm. A string that will be prepended to instance name to set the host name in nagios. So for instance the hostname would be something like:
  juju-squid-0
  If you're running multiple environments with the same services in them this allows you to differentiate between them.
* nagios\_down\_threshold | int

  Default: 50

  The percentage of downed squid peers that we care to alert on.
* nagios\_service\_type | string

  Default: generic

  What service this component forms part of, e.g. supermassive-squid-cluster. Used by nrpe.
* nagios\_servicegroups | string

  A comma-separated list of nagios servicegroups. If left empty, the nagios\_context will be used as the servicegroup.
* package\_status | string

  Default: install

  The status of service-affecting packages will be set to this value in the dpkg database. Useful valid values are "install" and "hold".
* port | int

  Default: 3128

  Squid listening port.
* port\_options | string

  Default: accel vhost

  Squid listening port options
* refresh\_patterns | string

  JSON- or YAML-formatted list of refresh patterns. For example: '{"http://www.ubuntu.com": {"min": 0, "percent": 20, "max": 60},
  "http://www.canonical.com": {"min": 0, "percent": 20, "max": 120}}'
* services | string

  Services definition(s). Although the variable type is a string, this is
  interpreted by the charm as yaml. To use multiple services within the
  same instance, specify all of the variables (service\_name,
  service\_host, service\_port) with a "-" before the first variable,
  service\_name, as below.

  + service\_name: example\_proxy
    service\_domain: example.com
    servers:
    - [foo.internal, 80]
    - [bar.internal, 80]
* services\_only\_from\_config | boolean

  Ignore services from relations unless configured in 'services'.
* snmp\_allowed\_ips | string

  Single, or json-formatted list of, IP (with optional subnet mask) allowed to query SNMP.
* snmp\_community | string

  SNMP community string for monitoring the service. Required for metrics to be enabled.
* snmp\_port | int

  Default: 3401

  Port for snmp service
* ssl\_cert | string

  Base64 encoded ssl cert file
* ssl\_certfile | string

  Default: /etc/squid3/ssl/cert.crt

  File path to ssl cert file inside deployed units
* ssl\_cipher\_suite | string

  Default: EECDH+AESGCM+AES128:EDH+AESGCM+AES128:EECDH+AES128:EDH+AES128:ECDH+AESGCM+AES128:aRSA+AESGCM+AES128:ECDH+AES128:DH+AES128:aRSA+AES128:EECDH+AESGCM:EDH+AESGCM:EECDH:EDH:ECDH+AESGCM:aRSA+AESGCM:ECDH:DH:aRSA:HIGH:!MEDIUM:!aNULL:!NULL:!LOW:!3DES:!DSS:!EXP:!PSK:!SRP

  SSL cipher suites.
* ssl\_key | string

  Base64 encoded ssl key file
* ssl\_keyfile | string

  Default: /etc/squid3/ssl/cert.key

  File path to ssl key file inside deployed units
* ssl\_options | string

  Default: NO\_SSLv2,NO\_SSLv3,CIPHER\_SERVER\_PREFERENCE,SINGLE\_DH\_USE

  SSL configuration options.
* target\_objs\_per\_dir | int

  Default: 400

  Target number of objects to store in L2 directories.
* upstream\_proxy\_address | string

  Address (hostname or IP) of an upstream (parent) Squid proxy. When set, all forward-proxy and auth\_list traffic will be sent through this upstream proxy instead of going directly to the internet. Reverse-proxy traffic to origin servers is unaffected.
* upstream\_proxy\_options | string

  Default: 0 default

  ICP port and cache\_peer options for the upstream proxy entry. The first token must be the ICP port (use 0 to disable ICP), followed by any cache\_peer options. For example, "0 default" or "3130 default no-query".
* upstream\_proxy\_port | int

  Default: 3128

  HTTP port of the upstream proxy.
* via | string

  Default: on

  Add 'Via' header to outgoing requests.
* wait\_for\_auth\_helper | boolean

  If true, do not start squid until an auth-helper relation is joined. This is useful if auth\_list configuration (e.g. "proxy\_auth REQUIRED") will cause squid to fail to start until an auth helper is available.
* x\_balancer\_name\_allowed | boolean

  Route based on X-Balancer-Name header set by Apache charm.
