Preview (0.x) — not production-ready. Use at your own risk.
Open Source · Preview · Go 1.25 v0.2.33

GoProxify

The distributed reverse proxy that never sleeps.
One Go binary. Three personalities. API & MCP to automate infra.

Go HTTP/3 WebSocket MCP PAT Adaptive LB Access Docker i18n

One binary. Three roles. Zero compromise.

Data plane, control plane and discovery in one Go binary — deploy the role you need, where you need it.

Data Plane · core mode

High-performance reverse proxy

HTTP/1–3 QUIC, L4 TCP/UDP. Adaptive LB from Agent metrics, inter-Core gateway, failover. In-memory TLS, WS control hub, encrypted local cache.

Control Plane · admin mode

UI, REST API & MCP server

Web UI (EN/FR/ES/DE), REST & MCP with scoped PAT. Domain delegation, error-page library, Access catalog & invites, multi-schedule backups, CLI (token/backup/alert/import).

Discovery · agent mode

Docker, Podman & Kubernetes

Read-only docker.sock (or Podman). goproxify.* labels, K8s watch. Live container metrics over WS for adaptive LB. Routes applied on the Core in real time.

High availability

Resilient by design

Each Core boots from an AES-256-GCM cache — autonomous without Admin. Raft Admin HA. Domain passthrough/terminate between Cores. Backend failover + quarantine.

Security

Defense in depth

OWASP CRS-4 WAF, rate limiting, Geo-IP, threat feeds. SSO / OIDC / SAML / LDAP / GitHub. Admin MFA. Security grade, Fail2Ban & CrowdSec. Scoped PAT for API & MCP.

Observability

Prism, metrics & audit

JSON access logs, Prometheus, OpenTelemetry. Prism analytics (Admin + per-Core) with Logs correlation. Audit with session or PAT actor. Live traffic views.

Access · SSH & shell portal

Operator access to VMs & containers

Web terminal + standard ssh with UUID sessions. Admin catalog & invites, per-user vault (SSH login + key/password), optional 2FA, HTML templates with SPA fallback.

Distributed architecture

Three independent, complementary components. The Core is the source of truth — Admin is reconstructible; the Core never sleeps.

goproxify — architecture
INTERNET :80 / :443 HTTP/1·2·3 QUIC CORE Data Plane · source of truth HTTP / TCP / UDP · Adaptive LB TLS in RAM — no keys on disk AES-256 cache · inter-Core gateway WS hub · hot reload · zero downtime :80 :443 :443/UDP :8000+WS ● HTTP/3 QUIC · failover boots without Admin (cache) proxies · certs · snippets · error pages WS full_sync WS push routes ADMIN Control Plane UI · REST · MCP · CLI PAT gpx_pat_* · i18n EN/FR/ES/DE ACME DNS-01 · domain delegation Alerting 10 channels · MFA Import nginx / Traefik / Caddy Backups · Prism · Raft HA SQLite · :9443 · JWT + PAT reconstructible from Cores users · teams · pairing tokens WS Agent → Core :8000 (metrics · routes) AGENT Docker · Podman · K8s Auto-discovery Read-only docker.sock Labels goproxify.* · K8s Watch Container metrics → Adaptive LB connects to Core (:8000 WS) optional — no SPOF Docker containers goproxify.enable=true goproxify.domain=app.example.com events

Get started in 5 minutes

A ready-to-run Admin + Core + Agent stack. Pick your method.

Generates hex-32 secrets, writes .env (chmod 600), checks Docker / ports, then starts Admin + Core + Agent.

shell
# Download then run (inspect before execute)
$ curl -fsSL https://github.com/Vincamok/goproxify/raw/public/main/scripts/quickstart.sh -o quickstart.sh
$ bash quickstart.sh

Admin UI → http://localhost:9443. Variants (run alone, never paste with the block above): bash quickstart.sh --print-secrets · bash quickstart.sh --env-only

Official GHCR images with floating :preview tag (0.x). Optional SemVer pin via versions.json.

shell
# 1. Fetch quickstart + env template
$ curl -LO https://github.com/Vincamok/goproxify/raw/public/main/docker-compose.quickstart.yml
$ curl -LO https://github.com/Vincamok/goproxify/raw/public/main/.env.example
$ cp .env.example .env
 
# 2. Fill secrets — or: bash quickstart.sh --env-only
$ # GPX_JWT_SECRET=$(openssl rand -hex 32)
$ # GPX_PAIRING_SECRET=$(openssl rand -hex 32)
 
# 3. Start Admin + Core + Agent
$ docker compose -f docker-compose.quickstart.yml up -d
 
# Admin UI → http://localhost:9443
.env (excerpt)
# Click the key icon to generate secrets in your browser
# Images (defaults = GHCR :preview)
# GOPROXIFY_ADMIN_TAG=preview
# GOPROXIFY_CORE_TAG=preview
# GOPROXIFY_AGENT_TAG=preview
# Required
GPX_JWT_SECRET=
GPX_PAIRING_SECRET=
GPX_FIRST_ADMIN_EMAIL=admin@example.com
GPX_FIRST_ADMIN_PASSWORD=

ADMIN_PORT=9443
Stacks → Add stack → Web editor. Pick a model, paste the compose, deploy. Admin on port 9443.

Paste the compose, then load stack.env (Advanced → Load variables from .env file) or set the same keys in Environment variables.

docker-compose.yml
# Portainer — model A: secrets via stack.env
networks:
  goproxify_net:
    name: goproxify_net

volumes:
  goproxify_admin_data:
  goproxify_core_data:
  goproxify_agent_data:

services:
  goproxify-admin:
    image: ghcr.io/vincamok/goproxify/admin:preview
    container_name: goproxify-admin
    restart: unless-stopped
    command: ["admin"]
    environment:
      - TZ=${TZ:-Europe/Paris}
      - GPX_SECURITY_JWT_SECRET=${GPX_JWT_SECRET}
      - GPX_PAIRING_SECRET=${GPX_PAIRING_SECRET}
      - GPX_FIRST_ADMIN_EMAIL=${GPX_FIRST_ADMIN_EMAIL}
      - GPX_FIRST_ADMIN_PASSWORD=${GPX_FIRST_ADMIN_PASSWORD}
      - GPX_IDENTITY_CORE_NODE_NAME=${CORE_NODE_NAME:-goproxify-core}
      - GPX_SERVER_API_PORT=9443
    ports:
      - "${ADMIN_PORT:-9443}:9443"
    volumes:
      - goproxify_admin_data:/etc/goproxify
    networks: [goproxify_net]

  goproxify-core:
    image: ghcr.io/vincamok/goproxify/core:preview
    container_name: goproxify-core
    restart: unless-stopped
    command: ["core"]
    environment:
      - TZ=${TZ:-Europe/Paris}
      - GPX_PAIRING_SECRET=${GPX_PAIRING_SECRET}
      - GPX_IDENTITY_CORE_NODE_NAME=${CORE_NODE_NAME:-goproxify-core}
    ports:
      - "${CORE_HTTP_PORT:-80}:80"
      - "${CORE_HTTPS_PORT:-443}:443"
      - "${CORE_HTTPS_PORT:-443}:443/udp"
    volumes:
      - goproxify_core_data:/etc/goproxify
    networks: [goproxify_net]
    depends_on: [goproxify-admin]

  goproxify-agent:
    image: ghcr.io/vincamok/goproxify/agent:preview
    container_name: goproxify-agent
    restart: unless-stopped
    command: ["agent"]
    environment:
      - TZ=${TZ:-Europe/Paris}
      - GPX_PAIRING_SECRET=${GPX_PAIRING_SECRET}
      - GPX_CONTROL_PLANE_CORE_ENDPOINT=http://goproxify-core:8000
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - goproxify_agent_data:/etc/goproxify
    networks: [goproxify_net]
    depends_on: [goproxify-core]
stack.env
# Click the key icon to generate secrets in your browser
# Nothing is sent to any server
GPX_JWT_SECRET=
GPX_PAIRING_SECRET=
GPX_FIRST_ADMIN_EMAIL=admin@example.com
GPX_FIRST_ADMIN_PASSWORD=
ADMIN_PORT=9443
TZ=Europe/Paris
CORE_NODE_NAME=goproxify-core

Single paste: replace CHANGE_ME_* before Deploy. No stack.env / env file needed.

docker-compose.yml
# Portainer — model B: inline secrets (no stack.env)
# Click the key icon to fill CHANGE_ME_* in your browser
networks:
  goproxify_net:
    name: goproxify_net

volumes:
  goproxify_admin_data:
  goproxify_core_data:
  goproxify_agent_data:

services:
  goproxify-admin:
    image: ghcr.io/vincamok/goproxify/admin:preview
    container_name: goproxify-admin
    restart: unless-stopped
    command: ["admin"]
    environment:
      - TZ=Europe/Paris
      - GPX_SECURITY_JWT_SECRET=CHANGE_ME_JWT_HEX32
      - GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32
      - GPX_FIRST_ADMIN_EMAIL=admin@example.com
      - GPX_FIRST_ADMIN_PASSWORD=CHANGE_ME_PASSWORD_MIN12
      - GPX_IDENTITY_CORE_NODE_NAME=goproxify-core
      - GPX_SERVER_API_PORT=9443
    ports:
      - "9443:9443"
    volumes:
      - goproxify_admin_data:/etc/goproxify
    networks: [goproxify_net]

  goproxify-core:
    image: ghcr.io/vincamok/goproxify/core:preview
    container_name: goproxify-core
    restart: unless-stopped
    command: ["core"]
    environment:
      - TZ=Europe/Paris
      - GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32
      - GPX_IDENTITY_CORE_NODE_NAME=goproxify-core
    ports:
      - "80:80"
      - "443:443"
      - "443:443/udp"
    volumes:
      - goproxify_core_data:/etc/goproxify
    networks: [goproxify_net]
    depends_on: [goproxify-admin]

  goproxify-agent:
    image: ghcr.io/vincamok/goproxify/agent:preview
    container_name: goproxify-agent
    restart: unless-stopped
    command: ["agent"]
    environment:
      - TZ=Europe/Paris
      - GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32
      - GPX_CONTROL_PLANE_CORE_ENDPOINT=http://goproxify-core:8000
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock:ro
      - goproxify_agent_data:/etc/goproxify
    networks: [goproxify_net]
    depends_on: [goproxify-core]
Core and Agent pair via the same GPX_PAIRING_SECRET. Secrets are generated in your browser only — nothing is sent to any server.

Chart in the repo (helm/goproxify). Requires global.authToken. Generate secrets in your browser, then helm install.

values-secrets.yaml
# Click the key icon — secrets stay in your browser
fullnameOverride: goproxify

global:
  authToken: ""
  timezone: Europe/Paris

admin:
  image:
    tag: "preview"
  config:
    jwtSecret: ""
  ingress:
    enabled: true
    host: admin.example.com

core:
  image:
    tag: "preview"

agent:
  image:
    tag: "preview"
shell
# 1. Clone chart (public/main)
$ git clone -b public/main https://github.com/Vincamok/goproxify.git && cd goproxify
 
# 2. Save values-secrets.yaml (from the block above), then install
$ helm upgrade --install goproxify ./helm/goproxify \
-n goproxify --create-namespace \
-f values-secrets.yaml
 
# Admin Service → port-forward or Ingress host
$ kubectl -n goproxify port-forward svc/goproxify-admin 8080:8080
shell
# Build from source (Go 1.25+)
$ git clone -b public/main https://github.com/Vincamok/goproxify.git && cd goproxify
$ go build -o goproxify ./cmd/goproxify
 
# Click the key icon to fill secrets (browser-only)
# Admin (control plane)
$ GPX_SECURITY_JWT_SECRET=CHANGE_ME_JWT_HEX32 \
GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32 \
./goproxify admin
 
# Core (data plane) — same pairing secret
$ GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32 \
GPX_IDENTITY_CORE_NODE_NAME=goproxify-core \
./goproxify core
 
# Agent (optional)
$ GPX_PAIRING_SECRET=CHANGE_ME_PAIRING_HEX32 \
GPX_CONTROL_PLANE_CORE_ENDPOINT=http://localhost:8000 \
./goproxify agent

10 alert channels

Each alert rule can notify multiple teams on multiple channels at once. Alertmanager-inspired model.

Email

SMTP configurable

Webhook

Slack, Discord, Teams…

ntfy.sh

Push mobile, self-hosted

Gotify

Push mobile, self-hosted

Jira

Création d'issue auto

Linear

Issue tracking moderne

GitHub Issues

Ouverture d'issue

GitLab Issues

Ouverture d'issue

Zammad

Ticketing open-source

GLPI

ITSM, API REST

Tech stack

Deliberate choices. No heavy framework, no hidden runtime — just Go and proven libraries.

Component Role Used in
Go 1.25
Single static binary, zero runtime to install, native cross-compilation Admin · Core · Agent
HTTP/3 QUIC
UDP transport via quic-go. Automatic Alt-Svc, 0-RTT, lower latency on degraded networks Core
SQLite (CGO-free)
Persistance without C deps. Cross-platform binary. Optional Raft cluster (3 nodes) for Admin HA Admin
WebSocket control plane
Persistent Admin↔Core and Agent↔Core tunnels. full_sync, live metrics for adaptive LB, inter-Core gateway Admin · Core · Agent
Cache AES-256-GCM
Encrypted routes & certs on disk. Core starts autonomously even if Admin is unreachable Core
Prometheus
/metrics endpoint on every component — drop-in Grafana integration Admin · Core · Agent
OpenTelemetry
Distributed request tracing. Configurable OTLP exporters (Jaeger, Tempo…) Core · Admin
Docker Engine API
Read-only via docker.sock. Real-time container events (start/stop/update) Agent
JWT + PAT
UI session (JWT). User API tokens gpx_pat_* with scopes for REST & MCP. Separate Core/Agent pairing tokens Admin
MCP
Model Context Protocol (JSON-RPC + SSE). Proxies, nodes, logs, audit tools… PAT required — Claude Desktop / Cursor ready Admin
ACME DNS-01
Automatic wildcard certs via OVH, Cloudflare, Gandi, Route53, Hetzner Admin → Core

Documentation

Guides, API contract, MCP server and version tracking — all in the repo.