How BareProxy Plan Shows What a Config Change Will Do Before It Goes Live
The riskiest moment in a proxy’s day is a config change. Cloudflare’s two outages at the end of 2025 both started with one that reached every server within seconds. BareProxy checks every config in full before it can go live, and plan goes one step further: it says which requests will be handled differently.
That works because BareProxy has no regular expressions and no scripting. Every matcher is an exact value, a prefix or a set, so the requests a site can receive fall into a finite number of classes, and every request in a class is handled the same way. plan works out what happens to each class under the old config and the new one, and prints the classes that change.

It compares effects. A rule that moves to another line with the same action is no change, so it isn’t reported. A rule that can never match, because earlier rules take all of its requests, gets a warning before it ships.
Each plan has an ID. bareproxy apply --plan 3c9e71 applies exactly that plan and refuses if anything changed since, so two people can’t apply over each other. See the full output on the demo page.