minimal reverse proxy for TLS protection of origin server
1.1K
Minimal reverse proxy to enable TLS protection of an origin server.
Originally extracted from an example of Federated Wiki.
Our multi-stage build starts with abiosoft/caddy building a custom
caddy with the jwt plugin. Our final image is alpine:3.7 with a
non-root user and our custom Caddyfile and a couple volumes.
See example in test/docker-compose.yml
ORIGIN (default: web:3000) names the host and port of the Origin Server.
CADYPATH (default: /etc/proxy) see volumes below.
TLS (default: self_signed) see https://caddyserver.com/docs/tls
/etc/proxy.d place to add extra Caddyfiles. All files with a
.caddyfile suffix will be included before the default config. This
is intended to allow a base domain to be forwarded to a default
service (defined by ORIGIN) while allowing subdomains to be directed
to other services.
/etc/proxy where auto-generated certs live.
My favorite features:
We include a small collection of tests which conform to TAP.
prove -v
# example results
t/proxy.t ..
1..8
ok - default config localtest.me
ok - Caddy default page
ok - default config subdomain.localtest.me
ok - Caddy default page
ok - override config localtest.me
ok - Caddy default page
ok - override config subdomain.localtest.me
ok - overriden page
ok
All tests successful.
Files=1, Tests=8, 6 wallclock secs ( 0.02 usr 0.00 sys + 1.76 cusr 0.51 csys = 2.29 CPU)
Result: PASS
Github and Dockerhub are configured to build master branch and tags.
git tag -am "" 0.10.12
git push --tags
I've tried to keep the git and docker versions in step with the version of Caddy that's packaged in the image. There have been changes in this build without changes in Caddy, in which case I have tagged like this:
git tag -am "" 0.10.10-note
git push --tags
Content type
Image
Digest
Size
22.2 MB
Last updated
about 7 years ago
docker pull dobbs/proxy