Country-based access control for reverse proxies (forwardAuth/ext_authz/auth_request)
4.7K
Geographic access control for reverse proxies: may this client's country reach the site? Your proxy asks geoveto about each request (Traefik forwardAuth, Caddy forward_auth, Envoy ext_authz, nginx auth_request). A 200 allows it; anything else denies it, and geoveto's response body is passed back to the visitor, so you can serve a custom explanation page.
A single static Go binary in a scratch image (amd64 and arm64): no shell, no libc, no package manager. It is sandboxed with Landlock and seccomp, and in serve mode it cannot open an outbound connection at all. Releases are signed and attested with cosign. Read the source README before deploying, in particular the section on X-Forwarded-For ordering.
Content type
Image
Digest
sha256:333b1b7e9…
Size
4.2 MB
Last updated
11 days ago
docker pull grepular/geovetoPulls:
414
Sep 21 to Sep 27