The Security and Performance Gateway
The Security and Performance Gateway
Nginx with embedded Lua scripting running the full security layer, Brotli compression, HTTP/3, and GeoIP2 geolocation.
Nginx + LuaJIT at the Edge
OpenResty is nginx with LuaJIT embedded directly in the request processing pipeline. Every HTTP request to your Magento store passes through OpenResty first, where Lua scripts execute the full security and performance layer before the request reaches Varnish or PHP. This is not a sidecar or external WAF — the security logic runs inside the web server process itself, adding microseconds of latency rather than milliseconds.
Security Layer
The security stack runs in Lua inside OpenResty. Suspicious clients get a proof-of-work challenge that a real browser solves in the background, and the challenge gets harder while a store is under sustained abuse. Each client's TLS and HTTP/2 behaviour is fingerprinted to tell real browsers from scripted tools. Layered rate limiting slows down abusive clients, and search engine crawlers are verified by forward-confirmed reverse DNS, so real Googlebot and Bingbot traffic is never challenged and SEO is not affected. Community threat intelligence from CrowdSec and an inline web application firewall with Magento-specific virtual patches complete the layer.
Compression and Protocol Support
Brotli compression is enabled for text-based responses (HTML, CSS, JavaScript, JSON), providing 15-25% better compression ratios than gzip. HTTP/3 with QUIC is served alongside HTTP/2, reducing connection establishment time and improving performance on lossy mobile networks. Both features are configured at the OpenResty level — the upstream Magento application does not need to be aware of them.
GeoIP2, Logging, and TLS
GeoIP2 geolocation data is available in every request, enabling country-level access rules and geographic routing decisions in Lua. Access logs are formatted as structured JSON, making them parseable by log aggregation tools without custom regex patterns. TLS certificates are issued and renewed automatically inside OpenResty itself, with no reload and no interruption to live traffic. Read the OpenResty + Lua docs for the full security and routing reference.
- OpenResty = nginx + LuaJIT embedded scripting
- Adaptive proof-of-work challenges for bot mitigation
- TLS and HTTP/2 fingerprinting of every client
- Layered rate limiting, tunable per store
- Verified search engine crawlers, never challenged
- CrowdSec community threat intelligence and inline WAF
- Brotli compression and HTTP/3 with QUIC
- GeoIP2 geolocation and JSON-formatted access logs
- Automatic TLS issuance and renewal without reloads

