Enterprise-Grade Identity Infrastructure & Zero-Trust Reverse Proxy
SecureAuthAPI is a robust, distributed Identity Provider (IdP) and Identity-Aware Proxy (IAP) designed to implement the Zero-Trust security model. Built to solve the complexities of modern microservice security, this project eliminates the need to write authentication logic in individual applications. Instead, it places a lightweight Go reverse proxy in front of internal services, automatically intercepting unauthenticated traffic and enforcing secure OAuth2 PKCE login flows against a central Java Spring Boot backend.
Inspired by enterprise architectures like Google's BeyondCorp, this platform handles asymmetric cryptographic token signing (RSA-signed JWTs), distributed session invalidation via Redis, and secure PostgreSQL persistence.
- Tech Stack and Key Features
- Architecture
- Getting Started & Installation
- Usage Guide
- Contribution and Governance
- Identity-Aware Proxy (IAP): A zero-trust reverse proxy that seamlessly protects underlying microservices.
- OAuth2 & OIDC Implementation: Full Authorization Code flow with PKCE, including
.well-knowndiscovery endpoints. - Asymmetric Cryptography: Secure RSA signing and verification for JSON Web Tokens (Access and ID tokens).
- Distributed Session Management: High-speed, highly available session tracking and invalidation using Redis.
- Role-Based Access Control (RBAC): Fine-grained access control at the identity provider level.
- Languages: Java 21, Go 1.21
- Frameworks: Spring Boot 3.3, Spring Security
- Databases/Caching: PostgreSQL, Redis
- Infrastructure: Docker, Docker Compose
- CI/CD & Tools: GitHub Actions, Swagger / OpenAPI
Internet
|
v
Identity-Aware Proxy
(Go)
Port 9000
|
+------------+------------+
| |
v v
SecureAuthAPI IdP Dummy Apps
(Spring Boot) (protected services)
Port 8080 Port 3000
|
+---- PostgreSQL
|
+---- Redis
- Docker & Docker Compose installed on your machine.
- Port
8080,9000, and3000must be available.
Clone the repository and spin up the entire distributed infrastructure using Docker Compose. This automatically builds the Java IdP, Go Proxy, Go internal dummy app, PostgreSQL database, and Redis cache.
# Clone the repository
git clone https://github.com/prxcode/secureauthapi.git
cd secureauthapi
# Build and start all services
docker-compose up --buildTo witness the end-to-end zero-trust flow in action:
-
Trigger the Proxy Interception Open a new Incognito/Private browser window and navigate to the protected application port:
http://localhost:9000The Go proxy will instantly detect you lack a session, generate a cryptographic PKCE challenge, and redirect you to the Identity Provider.
-
Authenticate On the IdP login page, use the default seeded database credentials:
- Username:
testuser - Password:
password123
- Username:
-
Verify the Secure Hand-off Upon successful authentication, the IdP returns you to the proxy, which verifies the RSA-signed JWT, stores the session in Redis, and permits your request to the dummy application.
You will see the target application's JSON response displaying the
iap_headerscontaining your verified JWT.
Contributions, issues, and feature requests are highly welcome.
- Fork the project.
- Create your feature branch (
git checkout -b feature/AmazingFeature). - Commit your changes (
git commit -m 'feat: Add some AmazingFeature'). - Push to the branch (
git push origin feature/AmazingFeature). - Open a Pull Request.
This project is distributed under the GNU General Public License v3.0 (GPL-3.0). See the LICENSE file for more information.
Designed and developed to demonstrate enterprise-grade backend systems engineering.
- Maintainer: Priyanshu
- GitHub: @prxcode