C0nw0nk/Nginx-Lua-Anti-DDoS ? reverse-engineered prompt

Reverse engineered prompt

Build me an Nginx Lua anti DDoS protection package that I can drop into an Nginx setup and turn on from the config.

It should watch incoming traffic, rate limit floods, and automatically show a simple browser puzzle page for a few seconds when attack like behavior is detected, then let real users through. I want support for IP allow and block lists, subnet ranges, user agent filtering, logging of pass and fail attempts, and basic request checks for suspicious URLs, query strings, headers, cookies, and POST data. It should also let me protect certain paths with a username and password prompt, and hide sensitive backend errors with a custom error page.

Please make it work for normal websites and HTTPS, with clear settings in one main Lua file, plus any needed Nginx config examples. If useful, include optional support for shared cache storage and Redis or memcached, but keep the default setup simple. Add readable comments and make it easy to customize.

Are you gonna build this?

make sure you review the code using coderabbit

Try freeSponsored — opens CodeRabbit in a new tab