Current Status
RPC Core has no built-in incoming client authentication. Its endpoints are reachable by anyone who can access your deployment’s network address.Securing Your Deployment
Since Lasso doesn’t have built-in authentication, use these strategies to secure your deployment:Reverse Proxy Authentication
Deploy Lasso behind a reverse proxy (nginx, Caddy, Traefik) with authentication. Apply the boundary to every exposed RPC, WebSocket, dashboard, and operational route. Core v0.5.0 exposes JSON metrics at/api/metrics/:chain and Prometheus text at /metrics; it does not expose a management API. For nginx, keep the authentication at the site level so it also covers WebSocket upgrades:
API Gateway
Use an API gateway (Kong, Tyk, AWS API Gateway) to add:- API key validation
- Rate limiting per key
- Usage tracking
- Multiple authentication methods
Network-Level Security
- Firewall rules: Restrict access by IP address
- VPC isolation: Deploy in private subnet, expose via load balancer
- VPN: Require VPN access to reach Lasso endpoints
- mTLS: Client certificate authentication at load balancer
Provider Authentication
Lasso authenticates with upstream RPC providers using API keys configured in your profile YAML:Best Practices
Internal Deployment
Deploy in private network, access via VPN or bastion host
Public Deployment
Use reverse proxy with authentication and rate limiting
Development
Bind to localhost only:
http: [ip: {127, 0, 0, 1}]Production
Layer multiple security controls (network + proxy + monitoring)
See Also
- Deployment - Security checklist
- Configuration - Provider API keys
- Docker - Container security best practices