Files
proxy/docs/index.md
T
wmantly c3cfd41a80 Add screenshots to README and docs site
Captured from a fresh theta-env install with demo data, via headless
Chrome + Playwright (scripted login, no manual UI interaction needed to
reproduce).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-15 15:41:12 -04:00

3.8 KiB

layout, title
layout title
default Home

Proxy

A reverse proxy and HTTPS termination service using OpenResty/nginx with a management API and web GUI.

Screenshots

Hosts Authentication
Host list Per-host SSO auth

Basic auth and SSO are mutually exclusive per host, with per-user password management once basic auth is enabled:

Per-host basic auth

Features

  • Automated HTTPS/SSL - Let's Encrypt integration with HTTP-01 and DNS-01 challenges
  • Wildcard SSL Certificates - Support for wildcard domains with automatic renewal
  • Multiple DNS Providers - Cloudflare, DigitalOcean, PorkBun, DuckDNS (free) integrations
  • Advanced Routing - Sophisticated wildcard domain matching (*, **)
  • RESTful API - Full programmatic control
  • Web Interface - User-friendly management GUI
  • High Performance - Unix socket-based host lookup for minimal latency

Quick Start

A single all-in-one image bundling OpenResty + the app + Redis:

git clone https://github.com/theta42/proxy.git
cd proxy && docker compose up -d --build

See the Docker Guide for configuration (OIDC/LDAP via app_* env) and fronting an SSO Manager.

Automated bare-metal installation

For modern Debian-based systems (Ubuntu 20.04+, Debian 11+):

wget -O - https://raw.githubusercontent.com/theta42/proxy/master/ops/install.sh | sudo bash

Requirements (bare metal)

  • Node.js 18+ (tested with 18.x, 20.x, 22.x)
  • OpenResty (nginx with Lua support)
  • Redis
  • Linux system with root access

Documentation

Use Cases

Development Teams

  • Host multiple projects on a single server with unique domains
  • Automatic SSL for all development sites
  • Easy configuration via API or web UI

Production Deployments

  • High-performance reverse proxy for microservices
  • Centralized SSL certificate management
  • Dynamic routing without nginx reloads

Personal Projects

  • Self-hosted services with automatic HTTPS
  • Wildcard certificates for unlimited subdomains
  • Simple management interface

Architecture

┌─────────────┐
│   Client    │
└──────┬──────┘
       │ HTTPS
       ▼
┌─────────────────────┐
│  OpenResty/Nginx    │
│  - SSL Termination  │
│  - Host Routing     │
└──────┬──────────────┘
       │ Unix Socket
       ▼
┌─────────────────────┐      ┌─────────────┐
│   Node.js API       │◄────►│    Redis    │
│  - Management       │      │  - Storage  │
│  - SSL Orchestration│      │  - Cache    │
└──────┬──────────────┘      └─────────────┘
       │
       ▼
┌─────────────────────┐
│  Backend Services   │
│  - Your Apps        │
└─────────────────────┘

Community

License

MIT License - See LICENSE for details.