The reverse proxy that guides every visitor to the right app.
Publish your services. GoProxify makes them reachable, protected, and easy to manage — without the jargon.
A reverse proxy lets you publish several websites on the internet — each with its own address (https://blog…, https://shop…, https://app…) — while the applications themselves stay behind, out of direct reach.
You run multiple apps or containers. Visitors open a normal web address for each site. They never talk to the containers directly.
GoProxify receives every visit and opens the right door: blog traffic goes to the blog, shop traffic to the shop — according to the rules you set.
From one place you decide which sites are public, which need a login, and how to keep them available if a machine fails.
Three pieces work together — here is what each one does for you day to day.
A clear web interface to run the whole setup: publish sites, attach domain names, invite teammates, schedule backups, and follow alerts — in your language (EN, FR, ES, DE).
Gateways are the public front door. They welcome visitors on your https://… addresses and send each one to the right site in your fleet — quietly, and at scale.
The Agent watches your containers (via Portainer or Docker) and tells the gateways what is running. When you start, stop or move an app, public routes stay in sync.
Your sites should not go dark because one machine hiccups. Gateways remember their settings, a spare gateway can take over, and unhealthy apps are skipped.
Putting sites on the internet invites bots and abuse. GoProxify helps you slow attacks, block threats, and ask for a login when a site should stay private.
Know who visits which site, spot errors quickly, and get notified where your team already works — without digging through server files.
When an operator needs a shell on a VM or container, they open a secure terminal in the browser. You invite people, set limits, and avoid sharing passwords in chat.
One Admin to steer everything, two gateways to welcome visitors, and one Agent linked to Portainer to follow your container fleet. Visitors reach those sites through normal internet addresses (https://…).
A ready-to-run Admin + Core + Agent stack. Pick your method.
Generates hex-32 secrets, writes .env (chmod 600), checks Docker / ports, then starts Admin + Core + Agent.
Admin UI → http://localhost:9443. Variants (run alone, never paste with the block above): bash quickstart.sh --print-secrets · bash quickstart.sh --env-only
Official GHCR images with floating :preview tag (0.x). Optional SemVer pin via versions.json.
# Click the key icon to generate secrets in your browser # Images (defaults = GHCR :preview) # GOPROXIFY_ADMIN_TAG=preview # GOPROXIFY_CORE_TAG=preview # GOPROXIFY_AGENT_TAG=preview # Required GPX_JWT_SECRET= GPX_PAIRING_SECRET= GPX_FIRST_ADMIN_EMAIL=admin@example.com GPX_FIRST_ADMIN_PASSWORD= ADMIN_PORT=9443
Paste the compose, then load stack.env (Advanced → Load variables from .env file) or set the same keys in Environment variables.
# Portainer — model A: secrets via stack.env
networks:
goproxify_net:
name: goproxify_net
volumes:
goproxify_admin_data:
goproxify_core_data:
goproxify_agent_data:
services:
goproxify-admin:
image: ghcr.io/vincamok/goproxify/admin:preview
container_name: goproxify-admin
restart: unless-stopped
command: ["admin"]
environment:
- TZ=${TZ:-Europe/Paris}
- GPX_SECURITY_JWT_SECRET=${GPX_JWT_SECRET}
- GPX_PAIRING_SECRET=${GPX_PAIRING_SECRET}
- GPX_FIRST_ADMIN_EMAIL=${GPX_FIRST_ADMIN_EMAIL}
- GPX_FIRST_ADMIN_PASSWORD=${GPX_FIRST_ADMIN_PASSWORD}
- GPX_IDENTITY_CORE_NODE_NAME=${CORE_NODE_NAME:-goproxify-core}
- GPX_SERVER_API_PORT=9443
ports:
- "${ADMIN_PORT:-9443}:9443"
volumes:
- goproxify_admin_data:/etc/goproxify
networks: [goproxify_net]
goproxify-core:
image: ghcr.io/vincamok/goproxify/core:preview
container_name: goproxify-core
restart: unless-stopped
command: ["core"]
environment:
- TZ=${TZ:-Europe/Paris}
- GPX_PAIRING_SECRET=${GPX_PAIRING_SECRET}
- GPX_IDENTITY_CORE_NODE_NAME=${CORE_NODE_NAME:-goproxify-core}
ports:
- "${CORE_HTTP_PORT:-80}:80"
- "${CORE_HTTPS_PORT:-443}:443"
- "${CORE_HTTPS_PORT:-443}:443/udp"
volumes:
- goproxify_core_data:/etc/goproxify
networks: [goproxify_net]
depends_on: [goproxify-admin]
goproxify-agent:
image: ghcr.io/vincamok/goproxify/agent:preview
container_name: goproxify-agent
restart: unless-stopped
command: ["agent"]
environment:
- TZ=${TZ:-Europe/Paris}
- GPX_PAIRING_SECRET=${GPX_PAIRING_SECRET}
- GPX_CONTROL_PLANE_CORE_ENDPOINT=http://goproxify-core:8000
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- goproxify_agent_data:/etc/goproxify
networks: [goproxify_net]
depends_on: [goproxify-core]
# Click the key icon to generate secrets in your browser # Nothing is sent to any server GPX_JWT_SECRET= GPX_PAIRING_SECRET= GPX_FIRST_ADMIN_EMAIL=admin@example.com GPX_FIRST_ADMIN_PASSWORD= ADMIN_PORT=9443 TZ=Europe/Paris CORE_NODE_NAME=goproxify-core
Single paste: replace CHANGE_ME_* before Deploy. No stack.env / env file needed.
# Portainer — model B: inline secrets (no stack.env) # Click the key icon to fill CHANGE_ME_* in your browser networks: goproxify_net: name: goproxify_net volumes: goproxify_admin_data: goproxify_core_data: goproxify_agent_data: services: goproxify-admin: image: ghcr.io/vincamok/goproxify/admin:preview container_name: goproxify-admin restart: unless-stopped command: ["admin"] environment: - TZ=Europe/Paris - GPX_SECURITY_JWT_SECRET=CHANGE_ME_JWT_HEX32 - GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32 - GPX_FIRST_ADMIN_EMAIL=admin@example.com - GPX_FIRST_ADMIN_PASSWORD=CHANGE_ME_PASSWORD_MIN12 - GPX_IDENTITY_CORE_NODE_NAME=goproxify-core - GPX_SERVER_API_PORT=9443 ports: - "9443:9443" volumes: - goproxify_admin_data:/etc/goproxify networks: [goproxify_net] goproxify-core: image: ghcr.io/vincamok/goproxify/core:preview container_name: goproxify-core restart: unless-stopped command: ["core"] environment: - TZ=Europe/Paris - GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32 - GPX_IDENTITY_CORE_NODE_NAME=goproxify-core ports: - "80:80" - "443:443" - "443:443/udp" volumes: - goproxify_core_data:/etc/goproxify networks: [goproxify_net] depends_on: [goproxify-admin] goproxify-agent: image: ghcr.io/vincamok/goproxify/agent:preview container_name: goproxify-agent restart: unless-stopped command: ["agent"] environment: - TZ=Europe/Paris - GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32 - GPX_CONTROL_PLANE_CORE_ENDPOINT=http://goproxify-core:8000 volumes: - /var/run/docker.sock:/var/run/docker.sock:ro - goproxify_agent_data:/etc/goproxify networks: [goproxify_net] depends_on: [goproxify-core]
Chart in the repo (helm/goproxify). Requires global.authToken. Generate secrets in your browser, then helm install.
# Click the key icon — secrets stay in your browser fullnameOverride: goproxify global: authToken: "" timezone: Europe/Paris admin: image: tag: "preview" config: jwtSecret: "" ingress: enabled: true host: admin.example.com core: image: tag: "preview" agent: image: tag: "preview"
Each alert rule can notify multiple teams on multiple channels at once. Alertmanager-inspired model.
SMTP configurable
Slack, Discord, Teams…
Push mobile, self-hosted
Push mobile, self-hosted
Création d'issue auto
Issue tracking moderne
Ouverture d'issue
Ouverture d'issue
Ticketing open-source
ITSM, API REST
Deliberate choices. No heavy framework, no hidden runtime — just Go and proven libraries.
| Component | Role | Used in |
|---|---|---|
|
Go 1.25
|
Single static binary, zero runtime to install, native cross-compilation | Admin · Core · Agent |
|
HTTP/3 QUIC
|
UDP transport via quic-go. Automatic Alt-Svc, 0-RTT, lower latency on degraded networks |
Core |
|
SQLite (CGO-free)
|
Persistance without C deps. Cross-platform binary. Optional Raft cluster (3 nodes) for Admin HA | Admin |
|
WebSocket control plane
|
Persistent Admin↔Core and Agent↔Core tunnels. full_sync, live metrics for adaptive LB, inter-Core gateway |
Admin · Core · Agent |
|
Cache AES-256-GCM
|
Encrypted routes & certs on disk. Core starts autonomously even if Admin is unreachable | Core |
|
Prometheus
|
/metrics endpoint on every component — drop-in Grafana integration |
Admin · Core · Agent |
|
OpenTelemetry
|
Distributed request tracing. Configurable OTLP exporters (Jaeger, Tempo…) | Core · Admin |
|
Docker Engine API
|
Read-only via docker.sock. Real-time container events (start/stop/update) |
Agent |
|
JWT + PAT
|
UI session (JWT). User API tokens gpx_pat_* with scopes for REST & MCP. Separate Core/Agent pairing tokens |
Admin |
|
MCP
|
Model Context Protocol (JSON-RPC + SSE). Proxies, nodes, logs, audit tools… PAT required — Claude Desktop / Cursor ready | Admin |
|
ACME DNS-01
|
Automatic wildcard certs via OVH, Cloudflare, Gandi, Route53, Hetzner | Admin → Core |
Guides, API contract, MCP server and version tracking — all in the repo.
Endpoints, JWT / PAT auth, pairing tokens.
Claude Desktop, Cursor — plug in a gpx_pat_*.
Admin ↔ Core ↔ Agent flows, WS control plane, adaptive LB & gateway.
Passthrough vs Terminate between entry Core and target Core.