<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Posts on BareProxy.com</title>
    <link>https://bareproxy.com/posts/</link>
    <description>Recent content in Posts on BareProxy.com</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 01 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://bareproxy.com/posts/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Introducing BareProxy, the Reverse Proxy That Explains Itself</title>
      <link>https://bareproxy.com/introducing-bareproxy-the-reverse-proxy-that-explains-itself/</link>
      <pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/introducing-bareproxy-the-reverse-proxy-that-explains-itself/</guid>
      <description>&lt;p&gt;Most applications use a small part of nginx. They terminate TLS, route by host and path, spread requests over backends that are up, change config without dropping traffic, and sometimes need to know what happened to one request. BareProxy is a reverse proxy for that part, with a core small enough to read in an afternoon.&lt;/p&gt;&#xA;&lt;p&gt;The whole config for a site with an API, a web front end and a &lt;code&gt;www&lt;/code&gt; redirect is 21 lines. A newcomer can read it in five minutes, and nothing in it depends on a precedence order: rules are tried from the top, and the first match wins.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How BareProxy Plan Shows What a Config Change Will Do Before It Goes Live</title>
      <link>https://bareproxy.com/how-bareproxy-plan-shows-what-a-config-change-will-do-before-it-goes-live/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/how-bareproxy-plan-shows-what-a-config-change-will-do-before-it-goes-live/</guid>
      <description>&lt;p&gt;The riskiest moment in a proxy&amp;rsquo;s day is a config change. Cloudflare&amp;rsquo;s two outages at the end of 2025 both started with one that reached every server within seconds. BareProxy checks every config in full before it can go live, and &lt;code&gt;plan&lt;/code&gt; goes one step further: it says which requests will be handled differently.&lt;/p&gt;&#xA;&lt;p&gt;That works because BareProxy has no regular expressions and no scripting. Every matcher is an exact value, a prefix or a set, so the requests a site can receive fall into a finite number of classes, and every request in a class is handled the same way. &lt;code&gt;plan&lt;/code&gt; works out what happens to each class under the old config and the new one, and prints the classes that change.&lt;/p&gt;</description>
    </item>
    <item>
      <title>One Record per Request: How BareProxy Tracing Works</title>
      <link>https://bareproxy.com/one-record-per-request-how-bareproxy-tracing-works/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/one-record-per-request-how-bareproxy-tracing-works/</guid>
      <description>&lt;p&gt;Every request BareProxy handles gets a random ID, sent to the backend and back to the client in a &lt;code&gt;BareProxy-Id&lt;/code&gt; header, and shown on every error page BareProxy writes. When someone reports a problem, they can quote it.&lt;/p&gt;&#xA;&lt;p&gt;Every request also leaves exactly one record: one JSON line with the rule that matched, the config version that handled it, every backend tried or passed over and why, and the timings. Records go to the trace log and stay in memory for quick lookups.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BareProxy Modules: Nine Add-Ons Around a Bare Core</title>
      <link>https://bareproxy.com/bareproxy-modules-nine-add-ons-around-a-bare-core/</link>
      <pubDate>Mon, 28 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/bareproxy-modules-nine-add-ons-around-a-bare-core/</guid>
      <description>&lt;p&gt;BareProxy Core does six things: proxying, TLS, routing, backend health, config changes and request tracing. Everything else is a module, compiled in only when you want it. A Bare build carries the core alone. A Full build carries every module.&lt;/p&gt;&#xA;&lt;p&gt;There are nine: Static, Compress, Cache, Limit, Auth, Split, Guard, Export and Fleet. Each plugs in at a fixed point in the request, before routing, as a rule&amp;rsquo;s action, around the backend call, on the response, on the record or on config changes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why BareProxy Routes on the Same Path It Forwards</title>
      <link>https://bareproxy.com/why-bareproxy-routes-on-the-same-path-it-forwards/</link>
      <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/why-bareproxy-routes-on-the-same-path-it-forwards/</guid>
      <description>&lt;p&gt;Many proxy bypasses share one cause: the proxy reads a path one way and the application reads it another. A rule that blocks &lt;code&gt;/admin/&lt;/code&gt; does nothing if the request arrives as &lt;code&gt;/api/%2e%2e/admin&lt;/code&gt; and the application decodes it after the proxy has let it through.&lt;/p&gt;&#xA;&lt;p&gt;BareProxy normalizes every path once. It decodes escapes of plain characters, resolves &lt;code&gt;.&lt;/code&gt; and &lt;code&gt;..&lt;/code&gt; segments, and merges runs of slashes. Then it routes on that form and sends the backend exactly the same form. Encoded slashes and backslashes are refused unless a site opts in.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
