We will be speaking at Meet Magento Germany on 22 October 2026. Come say hello.

Proudly supporting Mage-OS contributors — limited lifetime free access. Mage-OS contributors, please reach out. Terms, policies, and FAQ are still being finalized.

Containerized Stack

The Security and Performance Gateway

The Security and Performance Gateway

Nginx with embedded Lua scripting running the full security layer, Brotli compression, HTTP/3, and GeoIP2 geolocation.

Nginx + LuaJIT at the Edge

OpenResty is nginx with LuaJIT embedded directly in the request processing pipeline. Every HTTP request to your Magento store passes through OpenResty first, where Lua scripts execute the full security and performance layer before the request reaches Varnish or PHP. This is not a sidecar or external WAF — the security logic runs inside the web server process itself, adding microseconds of latency rather than milliseconds.

Security Layer

The security stack runs in Lua inside OpenResty. Suspicious clients get a proof-of-work challenge that a real browser solves in the background, and the challenge gets harder while a store is under sustained abuse. Each client's TLS and HTTP/2 behaviour is fingerprinted to tell real browsers from scripted tools. Layered rate limiting slows down abusive clients, and search engine crawlers are verified by forward-confirmed reverse DNS, so real Googlebot and Bingbot traffic is never challenged and SEO is not affected. Community threat intelligence from CrowdSec and an inline web application firewall with Magento-specific virtual patches complete the layer.

Compression and Protocol Support

Brotli compression is enabled for text-based responses (HTML, CSS, JavaScript, JSON), providing 15-25% better compression ratios than gzip. HTTP/3 with QUIC is served alongside HTTP/2, reducing connection establishment time and improving performance on lossy mobile networks. Both features are configured at the OpenResty level — the upstream Magento application does not need to be aware of them.

GeoIP2, Logging, and TLS

GeoIP2 geolocation data is available in every request, enabling country-level access rules and geographic routing decisions in Lua. Access logs are formatted as structured JSON, making them parseable by log aggregation tools without custom regex patterns. TLS certificates are issued and renewed automatically inside OpenResty itself, with no reload and no interruption to live traffic. Read the OpenResty + Lua docs for the full security and routing reference.

  • OpenResty = nginx + LuaJIT embedded scripting
  • Adaptive proof-of-work challenges for bot mitigation
  • TLS and HTTP/2 fingerprinting of every client
  • Layered rate limiting, tunable per store
  • Verified search engine crawlers, never challenged
  • CrowdSec community threat intelligence and inline WAF
  • Brotli compression and HTTP/3 with QUIC
  • GeoIP2 geolocation and JSON-formatted access logs
  • Automatic TLS issuance and renewal without reloads
OpenResty
Ready to experience OpenResty for your Magento?
Get Started

The Perfect Agentic “Playground” for Magento Operators.

Bring your own cloud key and Claude subscription. We ship the containerized Magento platform — you keep the keys, the data, and the control.

StoreFrame management hub Console view with a Claude Code session answering questions about a Magento store