static files

BareProxy Serves Hugo and Other Static Sites Straight From a Folder

A Hugo site is a folder of files. Serving it shouldn’t need one server for the files and another in front for TLS. BareProxy does both: copy the build output to a small server, point one rule at it, and the site is live over HTTPS and HTTP/2.

The rules are opinionated so that they need no rewrite language. /about/ serves about/index.html. /about redirects to /about/ when it’s a folder. Folders are never listed, and names that start with a dot, like .git, are never served. error 404 /404.html sends Hugo’s own 404 page for anything missing.

bareproxy explain showing the rule that matched, the file on disk, its type and the precompressed copies next to it

Nothing outside the folder can be reached. Every lookup goes through Go’s directory-confined file access, so .. tricks, encoded escapes and symlinks that lead out of the folder all end in a 404. Relative symlinks that stay inside still work.

Build-time work stays at build time. If the deploy step writes app.js.br and app.js.gz next to app.js, BareProxy sends the copy the client accepts. It doesn’t compress anything itself. ETags, conditional requests and byte ranges come from Go’s standard library, so browsers revalidate cheaply and video seeks work.

And because file serving is part of the core, it explains itself like everything else. explain names the file a request would get, or the files it looked for and didn’t find. When the site later grows an API, that’s one pool and one rule, not a second server. The demo page shows both.