Identity-Aware Proxy for On-Prem applications | MrTrustor's shiny blog
Edit: Added a note about JWT header validation. I have a couple internal systems that I run at home, and that I want to be able to access from outside. I want only my partner and myself to be able to access those systems, and I want that access to be as transparent as possible for her.
https://blog.mrtrustor.net/post/iap-on-prem/