# How to patch loadbalancer with security updates

**URL:** <https://forums.suse.com/t/how-to-patch-loadbalancer-with-security-updates/3108>\
**Category:** Rancher 1.x\
**Created:** [June 14, 2016, 10:55am UTC](https://forums.suse.com/t/how-to-patch-loadbalancer-with-security-updates/3108 "2016-06-14T10:55:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mishak](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/mishak/32/412_2.png) [@mishak](https://forums.suse.com/u/mishak)\
**Post date:** [June 14, 2016, 10:55am UTC](https://forums.suse.com/t/how-to-patch-loadbalancer-with-security-updates/3108/1 "2016-06-14T10:55:04Z")

</div>

I’m experimenting with patching loadbalancer for now to enable TLS 1.0 but current haproxy in image does not have CVE-2016-2107 fix. How would you update it?

Rancher 1.0.1  
rancher/agent-instance:v0.8.1 (rancher/load-balancer-service)  
haproxy 1.6.3 2015/12/25 (in rancher/agent-instance:v0.8.1)

Rancher 1.0.2 is [using also v0.8.1](https://github.com/rancher/rancher/releases/tag/v1.0.2) so upgrade to latest stable won’t help.

For now I’m considering keeping highest build version of same min.maj of haproxy on each host where HA is running and mounting it into LB containers.

@alena You [mentioned](https://github.com/rancher/rancher/issues/2179#issuecomment-225693908) that loadbalancer refactoring will introduce providers. How security updates will be done when it is finished?

---

<div class="post-metadata">

**Author:** ![alena](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/alena/32/50_2.png) [@alena](https://forums.suse.com/u/alena)\
**Post date:** [June 14, 2016, 5:24pm UTC](https://forums.suse.com/t/how-to-patch-loadbalancer-with-security-updates/3108/2 "2016-06-14T17:24:57Z")

</div>

@mishak you would just to enable it on the lb image. Current image is build from this [repo](https://github.com/rancher/agent-instance). Once you test the changes, you can create your PR against the current repo and ask @cloudnautique to review it. The new image would apply only to newly created LBs; existing LBs will have to be recreated to get the new image.

With the refactoring, the security updates should be submitted to the lb-controller repo (the image will be built from there), and we are yet to finalize system services update procedure - most likely it will be in-service upgrade offered to the user once the new image is uploaded to the dockerhub.
