Files
proxy/docs/index.md
T
wmantly d5df5baca1 Add DuckDNS as a free DNS provider option (#124)
DuckDNS's API is smaller than the other providers' (no list/read API,
no arbitrary sub-records, one A/AAAA + one TXT record per domain), so
domains are entered by the operator instead of auto-discovered, and
getRecords reads from public DNS since there's nothing else to query.
Documented as a free option in the README and DNS provider docs.
2026-07-13 23:41:09 -04:00

3.5 KiB

layout, title
layout title
default Home

Proxy

A reverse proxy and HTTPS termination service using OpenResty/nginx with a management API and web GUI.

Features

  • Automated HTTPS/SSL - Let's Encrypt integration with HTTP-01 and DNS-01 challenges
  • Wildcard SSL Certificates - Support for wildcard domains with automatic renewal
  • Multiple DNS Providers - Cloudflare, DigitalOcean, PorkBun, DuckDNS (free) integrations
  • Advanced Routing - Sophisticated wildcard domain matching (*, **)
  • RESTful API - Full programmatic control
  • Web Interface - User-friendly management GUI
  • High Performance - Unix socket-based host lookup for minimal latency

Quick Start

A single all-in-one image bundling OpenResty + the app + Redis:

git clone https://github.com/theta42/proxy.git
cd proxy && docker compose up -d --build

See the Docker Guide for configuration (OIDC/LDAP via app_* env) and fronting an SSO Manager.

Automated bare-metal installation

For modern Debian-based systems (Ubuntu 20.04+, Debian 11+):

wget -O - https://raw.githubusercontent.com/theta42/proxy/master/ops/install.sh | sudo bash

Requirements (bare metal)

  • Node.js 18+ (tested with 18.x, 20.x, 22.x)
  • OpenResty (nginx with Lua support)
  • Redis
  • Linux system with root access

Documentation

Use Cases

Development Teams

  • Host multiple projects on a single server with unique domains
  • Automatic SSL for all development sites
  • Easy configuration via API or web UI

Production Deployments

  • High-performance reverse proxy for microservices
  • Centralized SSL certificate management
  • Dynamic routing without nginx reloads

Personal Projects

  • Self-hosted services with automatic HTTPS
  • Wildcard certificates for unlimited subdomains
  • Simple management interface

Architecture

┌─────────────┐
│   Client    │
└──────┬──────┘
       │ HTTPS
       ▼
┌─────────────────────┐
│  OpenResty/Nginx    │
│  - SSL Termination  │
│  - Host Routing     │
└──────┬──────────────┘
       │ Unix Socket
       ▼
┌─────────────────────┐      ┌─────────────┐
│   Node.js API       │◄────►│    Redis    │
│  - Management       │      │  - Storage  │
│  - SSL Orchestration│      │  - Cache    │
└──────┬──────────────┘      └─────────────┘
       │
       ▼
┌─────────────────────┐
│  Backend Services   │
│  - Your Apps        │
└─────────────────────┘

Community

License

MIT License - See LICENSE for details.