Sign inSign up

senthora/edge-trust

By senthora

•Updated 5 months ago

Keeps nginx origin access restricted to trusted Cloudflare IP ranges

Image
Networking
Security
0

229

senthora/edge-trust repository overview

⁠Edge Trust

When running infrastructure behind Cloudflare, origin servers are expected to only accept traffic forwarded by Cloudflare proxies.

Without additional restrictions, attackers can bypass Cloudflare entirely and connect directly to the origin.

Edge Trust helps maintain a "dark origin" setup by keeping nginx trust configuration up to date with the latest published Cloudflare IP ranges.

⁠How does it work?

Edge Trust periodically fetches Cloudflare IP ranges and regenerates nginx trust configuration when changes are detected. Generated configuration files are then written to a shared volume and a reload signal file is created for nginx.

Your nginx container is expected to:

  • mount the generated configuration volume
  • include generated configuration files
  • watch for reload signal files
  • reload nginx when signals appear

Edge Trust does not reload nginx directly.

⁠Quick Start

Run Edge Trust using Docker Compose:

services:
  edge-trust:
    image: senthora/edge-trust:latest
    command:
      - --daemon
      - --interval=4h
      - run
    volumes:
      - nginx-dynamic:/etc/nginx/dynamic
      - trust-state:/var/lib/edge-trust
      - nginx-signal:/signal
    environment:
      CF_API_URL: https://api.cloudflare.com/client/v4/ips
      STATE_JSON_PATH: /var/lib/edge-trust/state.json
      NGINX_PROXY_SOURCES_PATH: /etc/nginx/dynamic/trusted-proxy-sources.conf
      NGINX_ORIGIN_ALLOWLIST_PATH: /etc/nginx/dynamic/origin-allowlist.conf
      NGINX_RELOAD_SIGNAL_PATH: /signal/nginx.reload
    healthcheck:
      test: ["CMD", "edge-trust", "healthcheck"]
      interval: 30s
      timeout: 3s
      retries: 3
    restart: unless-stopped

volumes:
  nginx-dynamic:
  trust-state:
  nginx-signal:

Start container:

docker compose up -d

Generated nginx configuration files will be written to:

/etc/nginx/dynamic

For full documentation read Edge Trust README⁠.

Tag summary

Content type

Image

Digest

sha256:918afdc66…

Size

3.4 MB

Last updated

5 months ago

docker pull senthora/edge-trust