The Platform

BareProxy is a bare core with add-on modules around it. The core does six things and stops there. Modules add the rest, one at a time, and the core needs none of them.

BareProxy Core

What it does How
Reverse proxy HTTP/1.1 and HTTP/2 from clients, HTTP/1.1 to backends. WebSocket and streamed responses pass straight through.
TLS Certificates from Let’s Encrypt or any ACME CA, obtained and renewed on their own, or loaded from files. TLS 1.2 minimum.
Routing By host name, exact path or path prefix, method and header. The first matching rule wins.
Backend health Active checks plus failure counting on live traffic. Requests go to the healthy backend with the fewest requests in flight.
Config changes A new config is checked in full, then swapped in at once. Requests in flight finish on the old one, removed backends drain, and one command rolls back.
Request tracing Every request gets an ID and leaves one record. why, tail, explain and plan read them.

Design Rules

  • Match on what you forward. The path is normalized once, routed on, and sent to the backend in that same form.
  • First match wins. Rules are read from the top. There is no precedence order to learn.
  • Matchers are exact values, prefixes or sets. No regular expressions, no variables, no scripting. That is what lets plan say exactly which requests a change affects.
  • A bad config never replaces a good one. Every config is checked in full on apply, on reload and at startup.
  • One record per request, and any record can be explained.
  • Nothing from outside the Go project. Go’s standard library and the Go team’s own packages, and nothing else.

How a Request Is Handled

  1. The connection arrives, and the TLS handshake picks the certificate and HTTP/1.1 or HTTP/2.
  2. BareProxy gives the request an ID, checks it and normalizes its path.
  3. The host picks the site, and the site’s rules are tried from the top.
  4. The rule answers directly, redirects, or names a pool.
  5. The pool picks the backend with the fewest requests in flight, and BareProxy forwards a fresh request to it, with one retry if the connection can’t be opened.
  6. The response streams back, and the request’s record is written.

The config behind all this fits on one page. The config reference has a complete example, and the modules page shows where each add-on plugs in.