๐Ÿš€ v4.0.0 โ€” Load balancing, caching & more

The reverse proxy
built for speed

ShieldFlare Proxy is a high-performance reverse proxy written in Go. Drop-in replacement for Apache and Nginx with automatic SSL, WebSockets, load balancing and a powerful config system.

โฌ‡๏ธ Download ๐Ÿ“– Documentation
$ curl -fsSL https://proxy.shieldflare.nl/install.sh | bash
<1ms
Latency overhead
10K+
Requests/second
~7MB
Binary size
0
Dependencies

Everything you need

A complete replacement for Apache and Nginx with a simple config format and powerful features.

๐Ÿ”’

Automatic SSL

Let's Encrypt certificates are automatically requested and renewed. No certbot needed.

โšก

WebSocket support

Full bidirectional WebSocket proxying. Works with Socket.io and any other WebSocket library.

๐Ÿ”€

Load balancing

Distribute traffic across multiple backends with the upstream directive and built-in health checks.

๐Ÿ’พ

In-memory cache

Cache GET responses in memory with a single config line to reduce backend load.

๐Ÿ›ก๏ธ

IP access control

Allow or deny specific IPs and ranges with simple allow/deny rules.

โฑ๏ธ

Rate limiting

Limit requests per minute per IP per location to protect against abuse.

๐Ÿ“

Static files & SPA

Serve static files directly with SPA support for React, Vue and other frameworks.

๐Ÿ“Š

Dashboard integration

Optionally link to your ShieldFlare account for live traffic stats and remote management.

Simple config format

Similar to Apache/Nginx but much simpler. Configs live in /etc/shieldflare-proxy/sites-available/

โœ“
Hot reload

Reload without downtime using SIGHUP or sf-proxy reload

โœ“
Validate before deploy

Use sf-proxy test to validate configs before enabling

โœ“
Per-vhost logging

Every site gets its own access log in /var/log/shieldflare-proxy/

conf
# /etc/shieldflare-proxy/sites-available/mysite.conf

server_name mysite.com www.mysite.com
ssl on
redirect_http on
gzip on

# IP access control
allow 10.0.0.0
deny all

location /api/ {
    upstream http://backend1:3000/
    upstream http://backend2:3000/
    rate_limit 100
    cache 60
}

location / {
    static /var/www/mysite/dist/
    spa on
}

Powerful CLI

Manage your sites from the command line.

bash
# Create and enable a site
sf-proxy create mysite.com http://127.0.0.1:3000
sf-proxy enable mysite.com

# View status and logs
sf-proxy status
sf-proxy logs mysite.com 100

# Reload without downtime
sf-proxy reload

# Link to ShieldFlare dashboard
sf-proxy dashboard https://shieldflare.nl YOUR_API_KEY my-server

Download

Download the binary or use the one-line installer.

๐Ÿง Linux x64
Ubuntu, Debian, CentOS, etc.
~7.5 MB
โฌ‡๏ธ Download
๐Ÿง Linux ARM64
Raspberry Pi, AWS Graviton, etc.
~6.9 MB
โฌ‡๏ธ Download
๐ŸชŸ Windows x64
Windows Server 2016+
~7.7 MB
โฌ‡๏ธ Download

Want dashboard management?

Link ShieldFlare Proxy to your ShieldFlare account for live traffic stats, log viewing, remote config management and DDoS protection.

Create free account โ†’ Learn more