<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pages on BareProxy.com</title>
    <link>https://bareproxy.com/pages/</link>
    <description>Recent content in Pages on BareProxy.com</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <atom:link href="https://bareproxy.com/pages/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>About</title>
      <link>https://bareproxy.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/about/</guid>
      <description>&lt;p&gt;BareProxy is a project at an early stage. It asks how little machinery it takes to provide the part of nginx that most applications use, and answers with a bare core and a set of add-on modules around it. Version 0.1 is an Alpha. This site shows where the project stands.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-the-project-exists&#34;&gt;Why the Project Exists&lt;/h2&gt;&#xA;&lt;p&gt;Most applications use a small part of nginx. They need TLS, routing by host name and path, requests spread over backends that are actually up, config changes that don&amp;rsquo;t drop traffic, and a way to find out what happened to a request when something breaks. The proxies that do this well carry decades of features most sites never touch. Each of those features is code that runs at the edge, in front of everything else.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://bareproxy.com/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/contact/</guid>
      <description>&lt;p&gt;The project would like to hear from:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Teams running nginx&lt;/strong&gt; who would like to try a smaller proxy on their own traffic.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Engineers&lt;/strong&gt; with a config, a traffic pattern or a failure the project should test against.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Anyone&lt;/strong&gt; with a question about the core, the modules or the figures on this site.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Write to &lt;strong&gt;&lt;a href=&#34;mailto:info@bareproxy.com&#34;&gt;info@bareproxy.com&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;If you are writing about your own setup, it helps to mention what you run today, roughly how many sites and backends sit behind it, and which nginx features you actually use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Platform</title>
      <link>https://bareproxy.com/platform/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/platform/</guid>
      <description>&lt;p&gt;BareProxy is a bare core with add-on modules around it. The core does six things and stops there. Modules add the rest, one at a time, and the core needs none of them.&lt;/p&gt;&#xA;&lt;h2 id=&#34;bareproxy-core&#34;&gt;BareProxy Core&lt;/h2&gt;&#xA;&lt;div style=&#34;overflow-x:auto&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;What it does&lt;/th&gt;&#xA;          &lt;th&gt;How&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Reverse proxy&lt;/td&gt;&#xA;          &lt;td&gt;HTTP/1.1 and HTTP/2 from clients, HTTP/1.1 to backends. WebSocket and streamed responses pass straight through.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;TLS&lt;/td&gt;&#xA;          &lt;td&gt;Certificates from Let&amp;rsquo;s Encrypt or any ACME CA, obtained and renewed on their own, or loaded from files. TLS 1.2 minimum.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Routing&lt;/td&gt;&#xA;          &lt;td&gt;By host name, exact path or path prefix, method and header. The first matching rule wins.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Backend health&lt;/td&gt;&#xA;          &lt;td&gt;Active checks plus failure counting on live traffic. Requests go to the healthy backend with the fewest requests in flight.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Config changes&lt;/td&gt;&#xA;          &lt;td&gt;A new config is checked in full, then swapped in at once. Requests in flight finish on the old one, removed backends drain, and one command rolls back.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Request tracing&lt;/td&gt;&#xA;          &lt;td&gt;Every request gets an ID and leaves one record. &lt;code&gt;why&lt;/code&gt;, &lt;code&gt;tail&lt;/code&gt;, &lt;code&gt;explain&lt;/code&gt; and &lt;code&gt;plan&lt;/code&gt; read them.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;design-rules&#34;&gt;Design Rules&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Match on what you forward.&lt;/strong&gt; The path is normalized once, routed on, and sent to the backend in that same form.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;First match wins.&lt;/strong&gt; Rules are read from the top. There is no precedence order to learn.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Matchers are exact values, prefixes or sets.&lt;/strong&gt; No regular expressions, no variables, no scripting. That is what lets &lt;code&gt;plan&lt;/code&gt; say exactly which requests a change affects.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;A bad config never replaces a good one.&lt;/strong&gt; Every config is checked in full on apply, on reload and at startup.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;One record per request,&lt;/strong&gt; and any record can be explained.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Nothing from outside the Go project.&lt;/strong&gt; Go&amp;rsquo;s standard library and the Go team&amp;rsquo;s own packages, and nothing else.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;how-a-request-is-handled&#34;&gt;How a Request Is Handled&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;The connection arrives, and the TLS handshake picks the certificate and HTTP/1.1 or HTTP/2.&lt;/li&gt;&#xA;&lt;li&gt;BareProxy gives the request an ID, checks it and normalizes its path.&lt;/li&gt;&#xA;&lt;li&gt;The host picks the site, and the site&amp;rsquo;s rules are tried from the top.&lt;/li&gt;&#xA;&lt;li&gt;The rule answers directly, redirects, or names a pool.&lt;/li&gt;&#xA;&lt;li&gt;The pool picks the backend with the fewest requests in flight, and BareProxy forwards a fresh request to it, with one retry if the connection can&amp;rsquo;t be opened.&lt;/li&gt;&#xA;&lt;li&gt;The response streams back, and the request&amp;rsquo;s record is written.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The config behind all this fits on one page. &lt;a href=&#34;https://bareproxy.com/config/&#34;&gt;The config reference&lt;/a&gt; has a complete example, and &lt;a href=&#34;https://bareproxy.com/modules/&#34;&gt;the modules&lt;/a&gt; page shows where each add-on plugs in.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
