release

BareProxy 0.1 Alpha Adds Plan, Apply and Rollback

BareProxy 0.1 Alpha is out. It adds the part of the design that makes a config change safe: plan says which requests a change will hand to a different place, apply makes it live, and rollback takes it back.

bareproxy plan compares the config file with the running config and lists the requests that change hands, in lines such as “example.com, any method, /api/v2 and below”. It warns about a rule that can never match. Each plan has an ID, and bareproxy apply --plan refuses if the file or the running config changed since, so two people can’t apply over each other.

bareproxy apply showing a plan and the swap to version 13, then bareproxy history listing five versions, the last one a rollback

apply checks the whole config again, opens any new listeners, swaps the config in with one atomic write and lets removed backends drain. The last 100 versions are kept, history lists them and rollback makes an earlier one live. Adding or removing a port no longer needs a restart. If the file is broken at startup, BareProxy runs the last good version and says so.

Tracing has the rest of its commands. tail follows records as they happen, with filters such as status>=500. status shows listeners, sites, backends and certificates, and events lists applies and backends going up and down. Records also stay in an in-memory store, so why finds a recent request fast. The trace log rotates, and a W3C traceparent header joins the application’s own trace.

The Alpha is tested with 100,000 generated requests. Each one runs through the server and through explain, and the two have to agree. plan is checked on 1,000 generated config pairs: every request whose handling changes must fall in a listed change, and every listed change must hold one. Broken configs, traversal and smuggling cases are covered too, and 96 tests pass in all. BareProxy was also measured against nginx 1.24, on the same machine with the same routes. The setup, the numbers and the caveats are in the results folder of the repository.

The demo now runs the real BareProxy code in your browser, compiled to WebAssembly. Check a config, explain a request and plan a change, with nothing sent anywhere.

BareProxy is open source under the Apache License 2.0. The code is on GitHub, and the download page has Linux binaries for amd64 and arm64 with SHA-256 checksums, and a first run for a Hugo site. macOS and Windows come later.

Next on the roadmap are automatic certificates, more hardening, and then macOS and Windows. The Alpha loads certificate files, so every HTTPS site needs one for now. The modules come after the core, starting with Compress, Limit and Split. If you try BareProxy on a site, or next to an nginx config, write to [email protected] and say what broke.