The Platform
BareProxy is a bare core with add-on modules around it. The core does six things and stops there. Modules add the rest, one at a time, and the core needs none of them.
BareProxy Core
| What it does | How |
|---|---|
| Reverse proxy | HTTP/1.1 and HTTP/2 from clients, HTTP/1.1 to backends. WebSocket and streamed responses pass straight through. |
| TLS | Certificates from Let’s Encrypt or any ACME CA, obtained and renewed on their own, or loaded from files. TLS 1.2 minimum. |
| Routing | By host name, exact path or path prefix, method and header. The first matching rule wins. |
| Backend health | Active checks plus failure counting on live traffic. Requests go to the healthy backend with the fewest requests in flight. |
| Config changes | A new config is checked in full, then swapped in at once. Requests in flight finish on the old one, removed backends drain, and one command rolls back. |
| Request tracing | Every request gets an ID and leaves one record. why, tail, explain and plan read them. |
Design Rules
- Match on what you forward. The path is normalized once, routed on, and sent to the backend in that same form.
- First match wins. Rules are read from the top. There is no precedence order to learn.
- Matchers are exact values, prefixes or sets. No regular expressions, no variables, no scripting. That is what lets
plansay exactly which requests a change affects. - A bad config never replaces a good one. Every config is checked in full on apply, on reload and at startup.
- One record per request, and any record can be explained.
- Nothing from outside the Go project. Go’s standard library and the Go team’s own packages, and nothing else.
How a Request Is Handled
- The connection arrives, and the TLS handshake picks the certificate and HTTP/1.1 or HTTP/2.
- BareProxy gives the request an ID, checks it and normalizes its path.
- The host picks the site, and the site’s rules are tried from the top.
- The rule answers directly, redirects, or names a pool.
- The pool picks the backend with the fewest requests in flight, and BareProxy forwards a fresh request to it, with one retry if the connection can’t be opened.
- The response streams back, and the request’s record is written.
The config behind all this fits on one page. The config reference has a complete example, and the modules page shows where each add-on plugs in.