Skip to main content

Current Status

RPC Core has no built-in incoming client authentication. Its endpoints are reachable by anyone who can access your deployment’s network address.
If you deploy Lasso publicly, ensure proper network-level security (firewall rules, VPC isolation, reverse proxy authentication) to restrict access.

Securing Your Deployment

Since Lasso doesn’t have built-in authentication, use these strategies to secure your deployment:

Reverse Proxy Authentication

Deploy Lasso behind a reverse proxy (nginx, Caddy, Traefik) with authentication. Apply the boundary to every exposed RPC, WebSocket, dashboard, and operational route. Core v0.5.0 exposes JSON metrics at /api/metrics/:chain and Prometheus text at /metrics; it does not expose a management API. For nginx, keep the authentication at the site level so it also covers WebSocket upgrades:
Replace the hostname, certificate paths, and password file. Keep Core bound to loopback or a private network address so clients cannot bypass the proxy. A collector scraping the JSON metrics API must authenticate too.

API Gateway

Use an API gateway (Kong, Tyk, AWS API Gateway) to add:
  • API key validation
  • Rate limiting per key
  • Usage tracking
  • Multiple authentication methods

Network-Level Security

  • Firewall rules: Restrict access by IP address
  • VPC isolation: Deploy in private subnet, expose via load balancer
  • VPN: Require VPN access to reach Lasso endpoints
  • mTLS: Client certificate authentication at load balancer

Provider Authentication

Lasso authenticates with upstream RPC providers using API keys configured in your profile YAML:
Set provider API keys as environment variables:
See Environment Variables for how profile files substitute variables supplied by your deployment. Core’s self-hosted boundary does not include managed accounts, billing, or incoming client keys. Use Lasso Cloud when you need those managed services.

Best Practices

Internal Deployment

Deploy in private network, access via VPN or bastion host

Public Deployment

Use reverse proxy with authentication and rate limiting

Development

Bind to localhost only: http: [ip: {127, 0, 0, 1}]

Production

Layer multiple security controls (network + proxy + monitoring)

See Also