Sign inSign up

cmdoss/auth-proxy

By cmdoss

โ€ขUpdated 3 months ago

A high-performance reverse proxy built with **OpenResty** and **Lua** designed to add a security ...

Buildkit cache
Image
0

3.1K

cmdoss/auth-proxy repository overview

โ OpenResty JWT Reverse Proxy

A high-performance reverse proxy built with OpenResty and Lua designed to add a security layer to private backend services. This proxy validates JSON Web Tokens (JWT) at the edge before traffic ever reaches your application.

โ ๐Ÿš€ Architecture

  1. Client sends a request with an Authorization: Bearer <token> header.
  2. OpenResty (this service) intercepts the request.
  3. Lua (in-memory) validates the JWT signature using your JWT_SECRET.
  4. If valid: The request is proxied to the configured UPSTREAM_URL.
  5. If invalid: A 401 Unauthorized is returned immediately, protecting your backend from load.

โ ๐Ÿ›  Setup & Deployment

โ 1. Environment Variables

You must set the following variable in your Railway project settings for this service:

VariableDescription
JWT_SECRETThe secret key used to sign and verify your tokens.
UPSTREAM_URLThe URL of the backend service to proxy requests to (e.g., http://my-backend-service:3000).
โ 2. Deployment

Since the Dockerfile is included, Railway will automatically detect and build the OpenResty environment with the lua-resty-jwt library installed via LuaRocks.


โ ๐Ÿ”’ Usage

โ Required Header

All requests must include the JWT in the following format:

Authorization: Bearer <your_jwt_token>
โ Backend Integration

When a request is successfully validated, this proxy forwards the request to your backend and injects the following header:

  • X-User-ID: Contains the sub (subject) claim from the JWT payload.

You can use this header in your web server to identify the user without re-verifying the token.


โ โšก Performance Benefits

  • No Sidecars: Validation happens inside the Nginx worker process.
  • Low Latency: Eliminates the extra network hop usually required for auth services.
  • Zero-Trust: Your backend web server can remain completely private (no public domain), accessible only through this authenticated gateway.

โ ๐Ÿงช Testing with Node.js

If you need to generate a token to test the proxy, you can use this snippet:

const jwt = require('jsonwebtoken');

const token = jwt.sign(
  { sub: '1234567890', name: 'John Doe' }, 
  process.env.JWT_SECRET, 
  { algorithm: 'HS256' }
);

console.log(`Bearer ${token}`);

โ License

This project is licensed under the Apache License 2.0.

Tag summary

Content type

Image

Digest

sha256:fbcefcfb1โ€ฆ

Size

155.6 MB

Last updated

3 months ago

docker pull cmdoss/auth-proxy