ShieldFlare Proxy is a high-performance reverse proxy written in Go. Drop-in replacement for Apache and Nginx with automatic SSL, WebSockets, load balancing and a powerful config system.
A complete replacement for Apache and Nginx with a simple config format and powerful features.
Let's Encrypt certificates are automatically requested and renewed. No certbot needed.
Full bidirectional WebSocket proxying. Works with Socket.io and any other WebSocket library.
Distribute traffic across multiple backends with the upstream directive and built-in health checks.
Cache GET responses in memory with a single config line to reduce backend load.
Allow or deny specific IPs and ranges with simple allow/deny rules.
Limit requests per minute per IP per location to protect against abuse.
Serve static files directly with SPA support for React, Vue and other frameworks.
Optionally link to your ShieldFlare account for live traffic stats and remote management.
Similar to Apache/Nginx but much simpler. Configs live in /etc/shieldflare-proxy/sites-available/
Reload without downtime using SIGHUP or sf-proxy reload
Use sf-proxy test to validate configs before enabling
Every site gets its own access log in /var/log/shieldflare-proxy/
# /etc/shieldflare-proxy/sites-available/mysite.conf server_name mysite.com www.mysite.com ssl on redirect_http on gzip on # IP access control allow 10.0.0.0 deny all location /api/ { upstream http://backend1:3000/ upstream http://backend2:3000/ rate_limit 100 cache 60 } location / { static /var/www/mysite/dist/ spa on }
Manage your sites from the command line.
# Create and enable a site sf-proxy create mysite.com http://127.0.0.1:3000 sf-proxy enable mysite.com # View status and logs sf-proxy status sf-proxy logs mysite.com 100 # Reload without downtime sf-proxy reload # Link to ShieldFlare dashboard sf-proxy dashboard https://shieldflare.nl YOUR_API_KEY my-server
Download the binary or use the one-line installer.
Link ShieldFlare Proxy to your ShieldFlare account for live traffic stats, log viewing, remote config management and DDoS protection.