ryan 368df3f76b chore(release): v3.3.0
### 🛠 修复
- 修复了 WAF 站点为空绑定规则时请求异常的问题,规范空站点绑定为数组并兼容历史 JSON 空值,避免请求时 Lua 处理失败。
- 修复了 WAF PoW 验证在部分场景下的异常。
- 修复了 Pages 部署文件列表请求与后端路由不一致的问题,并补充回归测试。
- 默认关闭 Redis maintenance notification 自动协商,并应用到平台与 Asynq 客户端,减少在不支持的 Redis 服务上的兼容性警告。
- 修复了 WAF 规则编辑器画布状态不稳定的问题:改用 React Flow 受控节点状态,支持删除节点与连线,节点属性仅在选中后展示。

### ⚡️ 优化与改进
- 新增 WAF 可组合规则可视化编排能力,提供基于 React Flow 的规则编辑器、有序图形 API 与运行时 DAG 执行;规则仅在 OpenResty reload 时发布,并通过校验和驱动的 IP 组快照在受界共享内存中协调。
- 完善 WAF 地域匹配数据,使用完整国家与一级行政区数据,国家选项同时显示中文名称与 ISO 代码,行政区支持按名称或代码搜索。
- Agent 现内置国家与城市地址库,首次启动无需下载即可使用地区匹配,并会在后续自动更新数据。
- 优化了 SQL 日志输出:常规查询日志下调至 debug 级别,慢查询与错误日志不再输出 SQL 文本,避免敏感参数在生产日志中暴露。

### 💄 其他/体验
- 优化了 WAF 规则编辑器初始视图,缩小编排区高度与首次适配缩放比例,默认显示更多画布上下文。
- 服务启动监听就绪后再打印服务横幅,避免在监听失败时显示误导性信息。
- 改进了日志打印输出。
2026-07-14 09:07:06 +08:00
2026-07-14 09:07:06 +08:00
2026-07-13 17:07:49 +08:00
2026-07-13 15:10:28 +08:00
2026-06-19 14:10:21 +08:00
2026-03-10 10:56:50 +08:00
2026-07-13 16:12:30 +08:00
2026-06-22 22:23:49 +08:00
2026-06-19 11:45:22 +08:00
2026-06-19 11:45:22 +08:00
2026-07-13 15:04:28 +08:00
2026-06-19 11:45:22 +08:00
2026-06-30 16:52:17 +08:00

OpenFlare

English | 📖 中文

OpenFlare is an open-source CDN orchestration and edge security platform. It supports reverse proxies, centralized configuration synchronization, secure intranet penetration (Tunnels), dynamic WAF protection, and anti-CC challenges.

license release ghcr

Warning

After logging in for the first time with the root user, make sure to change the default password 123456.

The BETA version is a temporary product for the development and testing phase. It may contain unknown issues and should not be used in production environments.

Documentation

https://open-flare.pages.dev

Quick links:

Core Features

  • Reverse Proxy Management: Website rules as the aggregation boundary, supporting multi-domain binding and multi-upstream load balancing with unified management of all OpenResty node configurations.
  • Immutable Config Version Control: Full-snapshot publish model based on version numbers (YYYYMMDD-NNN), with pre-publish diff preview, a single globally active version, and one-click sub-second rollback.
  • Secure Intranet Penetration (Tunnels): An open-source alternative to Cloudflare Tunnels. Securely expose local intranet Web services to the public network via Relay and OpenFlared clients — no public IP or open inbound ports required.
  • Edge WAF Safety Protection: Provides global and custom rule groups, supporting manual/automatic/subscription IP groups, MaxMind GeoIP country-level access control, Checksum-based differential IP group sync (no Nginx reload), and custom block responses.
  • Anti-CC & Human-Machine Challenge (PoW): Built-in high-performance client-side cryptographic Proof of Work challenges (similar to Turnstile) to block and intercept botnets and scrapers at the gateway edge in seconds.
  • Pages Static Hosting: Upload pre-built ZIP packages directly; edge Agents pull and serve them via local OpenResty, with SPA Fallback and built-in API reverse proxy configuration.
  • Automated TLS Certificate Management: Supports dynamic certificate upload, automatic multi-domain certificate matching and binding, and ACME-based automatic issuance and renewal via Let's Encrypt.
  • Uptime Kuma Monitoring Sync: Integrates with Uptime Kuma to automatically sync the monitoring site list using differential updates, providing real-time awareness of node availability and service health.
  • SSO Single Sign-On: Supports GitHub OAuth and standard OIDC protocol for seamless integration with enterprise identity providers.
  • Unified Observability: Aggregates node request metrics, real-time access log details, host/Nginx resource snapshots, health events, and a re-upload buffer for network fluctuations.

Quick Start

1. Launch Server

services:
  openflare:
    image: ghcr.io/rain-kl/openflare:latest
    restart: unless-stopped
    env_file: .env
    environment:
      TZ: ${TZ:-Asia/Shanghai}
    ports:
      - "3000:3000"
    volumes:
      - openflare_uploads:/app/uploads
    depends_on:
      postgres:
        condition: service_healthy
      redis:
        condition: service_healthy
      clickhouse:
        condition: service_healthy

  postgres:
    image: postgres:17-alpine
    restart: unless-stopped
    environment:
      POSTGRES_DB: ${DB_NAME:-openflare}
      POSTGRES_USER: ${DB_USERNAME:-openflare}
      POSTGRES_PASSWORD: ${DB_PASSWORD:-replace-with-strong-password}
    volumes:
      - openflare_postgres_data:/var/lib/postgresql/data
    healthcheck:
      test: ["CMD-SHELL", "pg_isready -U ${DB_USERNAME:-openflare} -d ${DB_NAME:-openflare}"]
      interval: 10s
      timeout: 5s
      retries: 5

  redis:
    image: valkey/valkey:8.0-alpine
    restart: unless-stopped
    command: ["valkey-server", "--appendonly", "yes"]
    volumes:
      - openflare_redis_data:/data
    healthcheck:
      test: ["CMD", "valkey-cli", "ping"]
      interval: 10s
      timeout: 5s
      retries: 5
      start_period: 5s

  clickhouse:
    image: clickhouse/clickhouse-server:25.3-alpine
    restart: unless-stopped
    environment:
      CLICKHOUSE_DB: ${CLICKHOUSE_NAME:-openflare}
      CLICKHOUSE_USER: ${CLICKHOUSE_USERNAME:-default}
      CLICKHOUSE_PASSWORD: ${CLICKHOUSE_PASSWORD:-replace-with-clickhouse-password}
      CLICKHOUSE_DEFAULT_ACCESS_MANAGEMENT: 1
      TZ: ${TZ:-Asia/Shanghai}
    volumes:
      - openflare_clickhouse_data:/var/lib/clickhouse
    healthcheck:
      test: ["CMD", "clickhouse-client", "--user", "${CLICKHOUSE_USERNAME:-default}", "--password", "${CLICKHOUSE_PASSWORD:-replace-with-clickhouse-password}", "--query", "SELECT 1"]
      interval: 10s
      timeout: 5s
      retries: 5
      start_period: 15s

volumes:
    openflare_uploads:
    openflare_postgres_data:
    openflare_redis_data:
    openflare_clickhouse_data:
docker compose up -d

Access at: http://localhost:3000

Default credentials:

  • Username: root
  • Password: 123456

2. Install Agent

Before installing an Agent, please install OpenResty on the target node first, or use the Agent Docker image with OpenResty built-in.

You can copy the installation command from Node Management -> Details -> Node Info -> Node Token & Deployment in the control panel, or directly use the scripts below:

Docker Deployment

For Docker deployment, you can directly run the Agent image:

docker pull ghcr.io/rain-kl/openflare-agent:latest
docker rm -f openflare-agent 2>/dev/null || true
docker run -d --name openflare-agent --restart unless-stopped \
  -p 80:80 -p 443:443/tcp -p 443:443/udp \
  -e OPENFLARE_SERVER_URL=http://your-server:3000 \
  -e OPENFLARE_AGENT_TOKEN=YOUR_AGENT_TOKEN \
  ghcr.io/rain-kl/openflare-agent:latest

Local Installation

Using discovery_token to register:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
  --server-url http://your-server:3000 \
  --discovery-token YOUR_DISCOVERY_TOKEN

Using node-specific agent_token:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/install-agent.sh | bash -s -- \
  --server-url http://your-server:3000 \
  --agent-token YOUR_AGENT_TOKEN

The installation script defaults to /opt/openflare-agent, creates a openflare-agent.service, automatically searches for openresty, and can be executed repeatedly to reinstall or upgrade the Agent.

3. Uninstall Agent

To completely uninstall the Agent and clear local data, run:

curl -fsSL https://raw.githubusercontent.com/Rain-kl/OpenFlare/main/scripts/uninstall-agent.sh | bash

The uninstallation script will stop and remove the openflare-agent.service, and delete the entire /opt/openflare-agent directory. It will not delete the local OpenResty installation.

4. Publish Your First Configuration

  1. Log in to the management panel and add a reverse proxy rule.
  2. View the preview or change summary before publishing.
  3. Activate the new version.
  4. Agents will receive the configuration and apply it via WebSocket notification or subsequent heartbeats.

The version number format is fixed as YYYYMMDD-NNN. Historical versions are immutable, and rollback is achieved by reactivating an older version.

UI Preview

Dashboard Overview

OpenFlare dashboard overview

Node Details

OpenFlare node detail

Proxy Configuration

OpenFlare version release

License

This project is licensed under Apache License 2.0.

Star History

Star History Chart
Languages
Go 56.6%
TypeScript 35.1%
CSS 4.7%
Lua 1.5%
HTML 0.8%
Other 1.2%