Im working on a project to expose private web services behind a firewall to the public internet but through a proxy that authenicates all requests.
Basically I have a public node.js process that does all the authentication, and redirects the requests to the appropriate endpoints. I'm using http-proxy to proxy the requests once I authenticate them.
Currently I have a node.js service running on all endpoints and I'm using openvpn to create the tunnel and iptables to redirect any requests that are not on localhost. The local node.js process manages adding and removing iptable rules and the authentication of the openvpn connection plus updating of the actual node.js code.
This works but is clunky and not hugely scalable.
I would like to pipe the http request from the public server through the websocket connection to the node.js process on the other side and redirect it to whatever ip:port its meant for.
Basic Network Diagram
Heres a basic network of what I'm trying to accomplish. I have tried to understand how pipes and streams would work together to accomplish this with no real success.
Can anyone provide me some basic sample code that would accomplish this?
![[1]:](https://i.stack.imgur.com/ZWuXH.png)