BareProxy Geo Rules Plugin: Allow, Block or Route Requests by Country
Status: planned, number 5 of 21 in BareProxy’s build order. The plugins are built easiest first, and this one is about a day of coding: a lookup in a local database file, then a header. It comes after the Redirects from a file plugin. This post describes what it will do, and it will be updated as it is built.
Some decisions depend on where a visitor is. A service licensed only in some countries. A login page that never sees a legitimate user from outside two countries but sees brute-force attempts from everywhere. A site with separate sections for different markets. Each app can look up the country itself, or the proxy can do it once and pass the answer on.
What It Will Do
- Look up the country of each request’s address in a local database file, such as the free GeoLite2 or DB-IP Lite databases, kept in a folder the plugin’s config names. No lookup leaves the machine.
- Allow or block by country, per site or per path prefix, with a page or a plain 403 for those turned away.
- Pass it on. Add the country code to the request in a header, such as
X-Country: DE, so the app can use it without a database of its own. - Route by country, the BareProxy way. The plugin sets the header, and an ordinary route rule matches on it:
route /* header X-Country=FR -> eu-pool. The routing stays in the config, whereplanandexplaincan see it.
A config will look something like this:
plugin geo /etc/bareproxy/plugins/geo-rules.wasm
config /etc/bareproxy/plugins/geo.json
read /var/lib/geoip
site example.com
use geo
route /* header X-Country=FR -> eu-app
route /* -> app
Limits Worth Knowing
Address-to-country data is good, not perfect: VPNs, mobile carriers and cloud providers move addresses around. Geo rules are a sensible filter, never proof of where someone is. The database file needs updating every few weeks; the plugin picks up a new file on its own, without a restart.
Every request it acts on carries a note in its record: the country it found, and the rule that used it.
The whole program is on the plugins page.