Aplicatiile (Java, Python, Node.js, PHP) nu trebuie sa se ocupe de SSL, WAF, rate limiting sau load balancing. Acestea sunt responsabilitati de infrastructura, centralizate intr-un strat reverse proxy.
Componente arhitecturale
- HAProxy — load balancer L4/L7 cu keepalived HA. Sticky sessions, health checks active, weighted round-robin
- Nginx — reverse proxy aplicativ pentru WebSocket, caching, compress (brotli/gzip), serve static
- Varnish — HTTP cache agresiv pentru aplicatii read-heavy
- Traefik — pentru containere Docker/K8s ingress cu auto-discovery
- ModSecurity — WAF cu OWASP Core Rule Set, blocaj injection attempts
- Let's Encrypt + Certbot — SSL auto-renewal centralizat
Functionalitati implementate standard
- SSL termination cu cipher hardening (TLS 1.3, HSTS, OCSP stapling)
- GeoIP filtering — blocaj tari fara trafic legitim
- IP whitelist/blacklist (CrowdSec sync, blocklist-uri custom)
- Rate limiting per IP si per endpoint (anti-scraping, anti-DDoS L7)
- Caching agresiv pentru endpoint-uri publice
- Compresie pre-cached pentru economisire bandwidth
Ce livram
Cluster reverse proxy HA, SSL auto-renewable, WAF cu false-positive reduction, dashboards monitoring, runbook pentru add/remove backend.
Exemplu: reverse proxy Nginx
Un bloc minim, gata de folosit, pentru o aplicatie in spatele Nginx cu TLS:
# /etc/nginx/conf.d/app.conf — reverse proxy + TLS
server {
listen 443 ssl;
server_name app.example.com;
ssl_certificate /etc/letsencrypt/live/app.example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/app.example.com/privkey.pem;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto $scheme;
}
}
HAProxy: backend cu health checks
Un backend HAProxy cu verificare activa a starii serverelor:
frontend web
bind *:443 ssl crt /etc/haproxy/certs/site.pem
default_backend app
backend app
balance leastconn
option httpchk GET /health
http-check expect status 200
server app1 10.0.0.11:8080 check inter 2s fall 3 rise 2
server app2 10.0.0.12:8080 check inter 2s fall 3 rise 2
Nginx: rate limiting anti-abuz
Limitezi cererile per IP ca sa opresti scraping-ul si atacurile L7:
# in http {}
limit_req_zone $binary_remote_addr zone=api:10m rate=10r/s;
# in location
location /api/ {
limit_req zone=api burst=20 nodelay;
limit_req_status 429;
proxy_pass http://app;
}
Nginx: cache pentru continut public
Cache-uiesti raspunsurile ca sa scazi incarcarea pe aplicatie:
# in http {}
proxy_cache_path /var/cache/nginx levels=1:2 keys_zone=app:50m max_size=2g inactive=60m;
# in location
location / {
proxy_cache app;
proxy_cache_valid 200 10m;
proxy_cache_use_stale error timeout updating;
add_header X-Cache $upstream_cache_status;
proxy_pass http://backend;
}
WAF: ModSecurity + OWASP CRS
Blochezi injectiile si atacurile L7 cu un WAF:
apt -y install libnginx-mod-http-modsecurity
# activezi + OWASP Core Rule Set
git clone https://github.com/coreruleset/coreruleset /etc/nginx/owasp-crs
# nginx.conf: modsecurity on; modsecurity_rules_file /etc/nginx/modsec/main.conf;
# incepi in DetectionOnly, apoi treci pe blocking dupa tuning
nginx -t && systemctl reload nginx