A high-performance reverse proxy built with **OpenResty** and **Lua** designed to add a security ...
3.1K
A high-performance reverse proxy built with OpenResty and Lua designed to add a security layer to private backend services. This proxy validates JSON Web Tokens (JWT) at the edge before traffic ever reaches your application.
Authorization: Bearer <token> header.JWT_SECRET.UPSTREAM_URL.401 Unauthorized is returned immediately, protecting your backend from load.You must set the following variable in your Railway project settings for this service:
| Variable | Description |
|---|---|
JWT_SECRET | The secret key used to sign and verify your tokens. |
UPSTREAM_URL | The URL of the backend service to proxy requests to (e.g., http://my-backend-service:3000). |
Since the Dockerfile is included, Railway will automatically detect and build the OpenResty environment with the lua-resty-jwt library installed via LuaRocks.
All requests must include the JWT in the following format:
Authorization: Bearer <your_jwt_token>
When a request is successfully validated, this proxy forwards the request to your backend and injects the following header:
X-User-ID: Contains the sub (subject) claim from the JWT payload.You can use this header in your web server to identify the user without re-verifying the token.
If you need to generate a token to test the proxy, you can use this snippet:
const jwt = require('jsonwebtoken');
const token = jwt.sign(
{ sub: '1234567890', name: 'John Doe' },
process.env.JWT_SECRET,
{ algorithm: 'HS256' }
);
console.log(`Bearer ${token}`);
This project is licensed under the Apache License 2.0.
Content type
Image
Digest
sha256:fbcefcfb1โฆ
Size
155.6 MB
Last updated
3 months ago
docker pull cmdoss/auth-proxy