تخطي إلى المحتوى الرئيسي
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.imgproxy-f9c9b4ff-4312-4ed8-ba21-d39b9d7f1502/image1_logolarge.png

imgproxy on Ubuntu 24.04 LTS by cloudimg

بواسطة cloudimg

imgproxy resizes, crops and converts images on the fly, with URL signing always on.

imgproxy is an open source server for processing images on demand. Your application builds a URL naming a source image and the work you want done, and imgproxy fetches that image, processes it and streams the result straight back. Image handling moves off your application servers entirely, and you stop pre generating and storing every rendition you might one day need.

Why imgproxy

  • Fast. Built on libvips, one of the fastest image processing libraries available, with a very low memory footprint.
  • Every modern format. Reads and writes JPEG, PNG, GIF, WebP, AVIF and JPEG XL, converting between them on the fly with a single URL change.
  • A complete processing grammar. Resize, crop to fill, smart crop, rotate, watermark, blur, sharpen, adjust quality and strip metadata, all expressed in the URL.
  • Stateless and simple. No database and no local state, so you scale out by adding instances behind a CDN or load balancer.

Secure by default from cloudimg

An image proxy that anyone can call is an abuse target, so this image ships locked down rather than open:

  • URL signing is always on. Every instance generates its own signing key and salt on first boot into a root only file, so unsigned requests are refused and no two deployments share a secret. The service is held back at boot until that key exists, so it can never start as an open proxy.
  • Source loading is hardened beyond the upstream default. Link local addresses are refused, which is what keeps the Azure Instance Metadata Service unreachable through the proxy, and so are loopback and private addresses, so it cannot be used to reach other hosts inside your virtual network. Upstream imgproxy permits private addresses by default; this image does not.
  • Abuse limits are set. Caps on source resolution, file size, redirects and request timeouts guard against decompression bombs.
  • A signing helper is included so you can mint a correctly signed URL in one command, plus a bundled sample image so the demo works the moment the instance boots.

imgproxy runs under systemd bound to the loopback interface, with nginx owning port 80 in front of it and an unauthenticated health probe for your load balancer. Put Azure Front Door, an Application Gateway or your own CDN in front to terminate TLS and cache processed renditions.

Licensing

imgproxy is open source under the Apache License 2.0 and free to use. This image ships the open source edition only and contains no imgproxy Pro components. The cloudimg charge covers packaging, hardening, security patching, image maintenance and 24/7 expert support.

لمحة سريعة

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.imgproxy-f9c9b4ff-4312-4ed8-ba21-d39b9d7f1502/image6_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.imgproxy-f9c9b4ff-4312-4ed8-ba21-d39b9d7f1502/image3_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.imgproxy-f9c9b4ff-4312-4ed8-ba21-d39b9d7f1502/image4_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.imgproxy-f9c9b4ff-4312-4ed8-ba21-d39b9d7f1502/image7_screenshot04.png
العربية (ليبيا)
أيقونة إلغاء الاشتراك في اختيارات خصوصيتك خيارات خصوصيتك
خصوصية صحة المستهلك خريطة الموقع اتصل بنا الخصوصية وملفات تعريف الارتباط شروط الاستخدام حول إعلاناتنا إدارة ملفات تعريف الارتباط