Reverst: Reverse Tunnels in Go over HTTP/3 and QUIC
github.com
github.com
Many other reverse proxy / tunneling solutions use TCP-based protocols or require the target hosts to be accessible by the proxy server, but in this case QUIC connection migration avoids the reconnection handshakes needed for dropped TCP connections, and your client->server model allows the robots to register themselves from restrictive networks.
The only missing feature would be to allow some sort of auth plugin - perhaps as a sub-request made to an external auth service that contains the identifier of the client the request will be routed to, similar to nginx's auth_request (https://nginx.org/en/docs/http/ngx_http_auth_request_module....)
https://linux.die.net/man/1/autossh
Few notes: manually add host machine key on first use. I add the parameters:
autossh -M 0 -o "ServerAliveInterval 30" -o "ServerAliveCountMax 3"Edit: This isn't hypothetical, either; I literally use curl regularly to query services. Sure, there are other options, but HTTP generally works, so...
Personally I work on two similar projects you might want to check out: zrok and OpenZiti. Similar projects, but zrok is closest to what you did here.
HTTP3 may not be suitable for all environments, as UDP is pretty commonly filtered.
If you are in such scenario, you may want to take a look at wstunnel, it allows you to do the same (and more) over websocket or HTTP2.
Do you have the protocol defined somewhere? Wstunnel is one of our options, and we'll likely add a golang library for the solution we chose. Would be easier if I don't have to figure out the frame format from code.
We are still looking into something like wstunnel and websockets, though I'm preparing myself for the day when we have to add "normal" http1.1 support :(
HAProxy implements something similar in HTTP/2 with the 'rhttp@' keyword.
edit: wrong URL.
We built something similar in https://github.com/namespacelabs/breakpoint but the more general purpose nature here is great.
I no longer need it in a CI context but I could imagine this getting really handy when some weird thing happens during the build stages of a docker container too.