Config Reference
A BareProxy config is one file. A line in the first column opens a block (global, site or pool), and the indented lines under it belong to it. Blocks don’t nest, and the whole grammar fits on one page.
This is a complete config for a site with an API, a web front end and a www redirect:
# /etc/bareproxy/bareproxy.conf
global
acme-email [email protected]
site example.com
route /healthz -> respond 200 "ok"
route /api/* -> api strip
route /* -> web
site www.example.com
route /* -> redirect 301 https://example.com
pool api
backend 10.0.0.11:8080
backend 10.0.0.12:8080
backend 10.0.0.13:8080
health /healthz
pool web
backend 10.0.0.21:3000
backend 10.0.0.22:3000
What It Does
site example.comserves HTTPS on port 443 with a certificate from Let’s Encrypt, and redirects plainhttp://requests tohttps://./healthzis answered by BareProxy itself, so a monitor can check the proxy without touching the application.- Everything under
/api/goes to poolapiwith the prefix stripped:/api/ordersreaches the backend as/orders. www.example.comredirects to a bare origin, so the path and query are kept.- Pool
apichecks each backend withGET /healthzevery 5 seconds. Poolwebhas no checks, so failed connections on live traffic take its backends out.
Rules
route [METHODS] PATH [header NAME[=VALUE]]... -> ACTION
/*matches every path./api/*matches/api,/api/and everything below it, never/apiv2. A path without/*matches only itself.- Methods are optional:
route GET,HEAD /assets/* -> web. header X-Betaneeds the header present;header X-Beta=1needs that value.- The action is a pool name (add
stripto drop the prefix),redirect CODE URL, orrespond STATUS [TEXT].
Commands
| Command | What it does |
|---|---|
bareproxy check |
Checks the config file. Needs no running server. |
bareproxy plan |
Shows what the file would change, compared with the running config. |
bareproxy apply |
Checks again, shows the plan, asks, and swaps the config in at once. |
bareproxy rollback |
Goes back to the previous version. |
bareproxy explain |
Shows how a request would be handled, without sending it. |
bareproxy why |
Tells the story of a request that already happened. |
bareproxy tail |
Follows request records as they happen. |
bareproxy status |
Listeners, sites, backends, certificates and recent error rates. |
The config file is the source of truth. After every apply or rollback it holds exactly the running config, so a restart never changes behavior. If the file is broken at startup, BareProxy runs the last good version and says so.