release

BareProxy 0.2.0 Runs WebAssembly Plugins Through the Proxy-Wasm Interface

BareProxy 0.2.0 is out, and it can run plugins. A plugin is a WebAssembly module, written to Proxy-Wasm, the plugin interface Envoy and Istio use, and run on wazero, a WebAssembly runtime in pure Go. So BareProxy is still one static binary on Linux, macOS and Windows. No plugin ships in this release. This one is the socket they plug into.

In a config it looks like this:

plugin crawlers /etc/bareproxy/plugins/crawlers.wasm
  config /etc/bareproxy/plugins/crawlers.json
  on-error open

site example.com
  use crawlers
  route /* -> files /var/www/example/public

What a Plugin Can Do

A site’s plugins see each request after the site is found and before routing. A plugin can change the headers, the method or the path, and then the core routes what it gets. It can answer the request itself. On the way back it sees the response headers and, if it asks, the whole body. Once the response is sent, it gets a last look for its own logging.

Everything else it has to ask for. No files, no network, no environment. A config line can give it a folder to read, a store of its own on disk, or addresses it may call, one by one. Each plugin has a memory cap and a time limit per call, 5 ms by default. A plugin that crashes or loops loses its instance, the request goes on without it or gets a 502, your choice per plugin, and a fresh instance starts in the background.

Nothing Hides From Explain

That last part matters most for BareProxy. Plugins could easily become the blind spot of a server whose whole point is saying what it did and why. So they aren’t one.

why shows what each plugin did to a request: went on, answered 403, replaced the response, failed. It shows how long each one took and the notes it wrote. plan lists a plugin file that changed even when the config text didn’t. The history keeps the exact plugin files each version ran, so a rollback runs the old module, not whatever sits at that path today. status shows how many instances of each plugin are working.

The Number That Isn’t Good Yet

It is measured. With the test plugin, which is written in Go, a plugin that does nothing adds about 42 microseconds to a request, and one that adds a header adds about 85. The design budget was 10. Most of that time is spent inside the plugin, starting Go’s runtime on every call. A plugin written in Rust or C should cost much less; that gets measured when the first real one is built. The numbers are in the results folder.

Next

The first plugins: AI crawler control, then RenderCache. The plugins page has the whole program, and the README has every setting. Binaries are on the releases page.