<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>BareProxy.com</title>
    <link>https://bareproxy.com/</link>
    <description>Recent content on BareProxy.com</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 01 Oct 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://bareproxy.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Introducing BareProxy, the Reverse Proxy That Explains Itself</title>
      <link>https://bareproxy.com/introducing-bareproxy-the-reverse-proxy-that-explains-itself/</link>
      <pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/introducing-bareproxy-the-reverse-proxy-that-explains-itself/</guid>
      <description>&lt;p&gt;Most applications use a small part of nginx. They terminate TLS, route by host and path, spread requests over backends that are up, change config without dropping traffic, and sometimes need to know what happened to one request. BareProxy is a reverse proxy for that part, with a core small enough to read in an afternoon.&lt;/p&gt;&#xA;&lt;p&gt;The whole config for a site with an API, a web front end and a &lt;code&gt;www&lt;/code&gt; redirect is 21 lines. A newcomer can read it in five minutes, and nothing in it depends on a precedence order: rules are tried from the top, and the first match wins.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How BareProxy Plan Shows What a Config Change Will Do Before It Goes Live</title>
      <link>https://bareproxy.com/how-bareproxy-plan-shows-what-a-config-change-will-do-before-it-goes-live/</link>
      <pubDate>Wed, 30 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/how-bareproxy-plan-shows-what-a-config-change-will-do-before-it-goes-live/</guid>
      <description>&lt;p&gt;The riskiest moment in a proxy&amp;rsquo;s day is a config change. Cloudflare&amp;rsquo;s two outages at the end of 2025 both started with one that reached every server within seconds. BareProxy checks every config in full before it can go live, and &lt;code&gt;plan&lt;/code&gt; goes one step further: it says which requests will be handled differently.&lt;/p&gt;&#xA;&lt;p&gt;That works because BareProxy has no regular expressions and no scripting. Every matcher is an exact value, a prefix or a set, so the requests a site can receive fall into a finite number of classes, and every request in a class is handled the same way. &lt;code&gt;plan&lt;/code&gt; works out what happens to each class under the old config and the new one, and prints the classes that change.&lt;/p&gt;</description>
    </item>
    <item>
      <title>One Record per Request: How BareProxy Tracing Works</title>
      <link>https://bareproxy.com/one-record-per-request-how-bareproxy-tracing-works/</link>
      <pubDate>Tue, 29 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/one-record-per-request-how-bareproxy-tracing-works/</guid>
      <description>&lt;p&gt;Every request BareProxy handles gets a random ID, sent to the backend and back to the client in a &lt;code&gt;BareProxy-Id&lt;/code&gt; header, and shown on every error page BareProxy writes. When someone reports a problem, they can quote it.&lt;/p&gt;&#xA;&lt;p&gt;Every request also leaves exactly one record: one JSON line with the rule that matched, the config version that handled it, every backend tried or passed over and why, and the timings. Records go to the trace log and stay in memory for quick lookups.&lt;/p&gt;</description>
    </item>
    <item>
      <title>BareProxy Modules: Nine Add-Ons Around a Bare Core</title>
      <link>https://bareproxy.com/bareproxy-modules-nine-add-ons-around-a-bare-core/</link>
      <pubDate>Mon, 28 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/bareproxy-modules-nine-add-ons-around-a-bare-core/</guid>
      <description>&lt;p&gt;BareProxy Core does six things: proxying, TLS, routing, backend health, config changes and request tracing. Everything else is a module, compiled in only when you want it. A Bare build carries the core alone. A Full build carries every module.&lt;/p&gt;&#xA;&lt;p&gt;There are nine: Static, Compress, Cache, Limit, Auth, Split, Guard, Export and Fleet. Each plugs in at a fixed point in the request, before routing, as a rule&amp;rsquo;s action, around the backend call, on the response, on the record or on config changes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Why BareProxy Routes on the Same Path It Forwards</title>
      <link>https://bareproxy.com/why-bareproxy-routes-on-the-same-path-it-forwards/</link>
      <pubDate>Sun, 27 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/why-bareproxy-routes-on-the-same-path-it-forwards/</guid>
      <description>&lt;p&gt;Many proxy bypasses share one cause: the proxy reads a path one way and the application reads it another. A rule that blocks &lt;code&gt;/admin/&lt;/code&gt; does nothing if the request arrives as &lt;code&gt;/api/%2e%2e/admin&lt;/code&gt; and the application decodes it after the proxy has let it through.&lt;/p&gt;&#xA;&lt;p&gt;BareProxy normalizes every path once. It decodes escapes of plain characters, resolves &lt;code&gt;.&lt;/code&gt; and &lt;code&gt;..&lt;/code&gt; segments, and merges runs of slashes. Then it routes on that form and sends the backend exactly the same form. Encoded slashes and backslashes are refused unless a site opts in.&lt;/p&gt;</description>
    </item>
    <item>
      <title>About</title>
      <link>https://bareproxy.com/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/about/</guid>
      <description>&lt;p&gt;BareProxy is a project at an early stage. It asks how little machinery it takes to provide the part of nginx that most applications use, and answers with a bare core and a set of add-on modules around it. Version 0.1 is an Alpha. This site shows where the project stands.&lt;/p&gt;&#xA;&lt;h2 id=&#34;why-the-project-exists&#34;&gt;Why the Project Exists&lt;/h2&gt;&#xA;&lt;p&gt;Most applications use a small part of nginx. They need TLS, routing by host name and path, requests spread over backends that are actually up, config changes that don&amp;rsquo;t drop traffic, and a way to find out what happened to a request when something breaks. The proxies that do this well carry decades of features most sites never touch. Each of those features is code that runs at the edge, in front of everything else.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Config Reference</title>
      <link>https://bareproxy.com/config/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/config/</guid>
      <description>&lt;p&gt;A BareProxy config is one file. A line in the first column opens a block (&lt;code&gt;global&lt;/code&gt;, &lt;code&gt;site&lt;/code&gt; or &lt;code&gt;pool&lt;/code&gt;), and the indented lines under it belong to it. Blocks don&amp;rsquo;t nest, and the whole grammar fits on one page.&lt;/p&gt;&#xA;&lt;p&gt;This is a complete config for a site with an API, a web front end and a &lt;code&gt;www&lt;/code&gt; redirect:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;# /etc/bareproxy/bareproxy.conf&#xA;global&#xA;  acme-email ops@example.com&#xA;&#xA;site example.com&#xA;  route /healthz -&amp;gt; respond 200 &amp;#34;ok&amp;#34;&#xA;  route /api/* -&amp;gt; api strip&#xA;  route /* -&amp;gt; web&#xA;&#xA;site www.example.com&#xA;  route /* -&amp;gt; redirect 301 https://example.com&#xA;&#xA;pool api&#xA;  backend 10.0.0.11:8080&#xA;  backend 10.0.0.12:8080&#xA;  backend 10.0.0.13:8080&#xA;  health /healthz&#xA;&#xA;pool web&#xA;  backend 10.0.0.21:3000&#xA;  backend 10.0.0.22:3000&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;what-it-does&#34;&gt;What It Does&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;code&gt;site example.com&lt;/code&gt; serves HTTPS on port 443 with a certificate from Let&amp;rsquo;s Encrypt, and redirects plain &lt;code&gt;http://&lt;/code&gt; requests to &lt;code&gt;https://&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;/healthz&lt;/code&gt; is answered by BareProxy itself, so a monitor can check the proxy without touching the application.&lt;/li&gt;&#xA;&lt;li&gt;Everything under &lt;code&gt;/api/&lt;/code&gt; goes to pool &lt;code&gt;api&lt;/code&gt; with the prefix stripped: &lt;code&gt;/api/orders&lt;/code&gt; reaches the backend as &lt;code&gt;/orders&lt;/code&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;code&gt;www.example.com&lt;/code&gt; redirects to a bare origin, so the path and query are kept.&lt;/li&gt;&#xA;&lt;li&gt;Pool &lt;code&gt;api&lt;/code&gt; checks each backend with &lt;code&gt;GET /healthz&lt;/code&gt; every 5 seconds. Pool &lt;code&gt;web&lt;/code&gt; has no checks, so failed connections on live traffic take its backends out.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;rules&#34;&gt;Rules&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;route [METHODS] PATH [header NAME[=VALUE]]... -&amp;gt; ACTION&lt;/code&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://bareproxy.com/contact/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/contact/</guid>
      <description>&lt;p&gt;The project would like to hear from:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Teams running nginx&lt;/strong&gt; who would like to try a smaller proxy on their own traffic.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Engineers&lt;/strong&gt; with a config, a traffic pattern or a failure the project should test against.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Anyone&lt;/strong&gt; with a question about the core, the modules or the figures on this site.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Write to &lt;strong&gt;&lt;a href=&#34;mailto:info@bareproxy.com&#34;&gt;info@bareproxy.com&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;&#xA;&lt;p&gt;If you are writing about your own setup, it helps to mention what you run today, roughly how many sites and backends sit behind it, and which nginx features you actually use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Demo</title>
      <link>https://bareproxy.com/demo/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/demo/</guid>
      <description>&lt;p&gt;BareProxy&amp;rsquo;s own commands, run against the config on the &lt;a href=&#34;https://bareproxy.com/config/&#34;&gt;config reference&lt;/a&gt; page. Each one reads the same compiled config the proxy routes with, so what it prints is what the proxy does.&lt;/p&gt;&#xA;&lt;h2 id=&#34;explain-a-request-before-it-arrives&#34;&gt;Explain a Request Before It Arrives&lt;/h2&gt;&#xA;&lt;p&gt;&lt;code&gt;explain&lt;/code&gt; walks the rules from the top, says why each one did or didn&amp;rsquo;t match, and shows which backend would get the request right now.&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ bareproxy explain GET https://example.com/api/orders&#xA;Running config, version 12&#xA;Site example.com (line 5): exact host match&#xA;  line 6   route /healthz -&amp;gt; respond 200 &amp;#34;ok&amp;#34;   no: path is not /healthz&#xA;  line 7   route /api/* -&amp;gt; api strip            match&#xA;Sent upstream as GET /orders with Host: example.com&#xA;Pool api (line 13): 2 of 3 up, fewest in flight wins&#xA;  10.0.0.11:8080   up, 0 in flight              next pick&#xA;  10.0.0.12:8080   up, 2 in flight&#xA;  10.0.0.13:8080   down since 14:02:10, 3 failed checks&#xA;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;ask-what-happened-to-a-request&#34;&gt;Ask What Happened to a Request&lt;/h2&gt;&#xA;&lt;p&gt;Every response carries a &lt;code&gt;BareProxy-Id&lt;/code&gt; header, and every error page shows it. Give any unique part of it to &lt;code&gt;why&lt;/code&gt;:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Modules</title>
      <link>https://bareproxy.com/modules/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/modules/</guid>
      <description>&lt;p&gt;Everything outside the core is a module. Modules are compiled in when BareProxy is built, so a binary without a module carries none of its code. Official builds come in two forms: Bare, the core alone, and Full, the core with every module. &lt;code&gt;bareproxy modules&lt;/code&gt; lists what a binary contains.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://bareproxy.com/images/modules-diagram.png&#34; alt=&#34;The request pipeline of BareProxy Core, with each module attached at its plug-in point&#34;&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-nine-modules&#34;&gt;The Nine Modules&lt;/h2&gt;&#xA;&lt;div style=&#34;overflow-x:auto&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Module&lt;/th&gt;&#xA;          &lt;th&gt;What it adds&lt;/th&gt;&#xA;          &lt;th&gt;Where it plugs in&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Static&lt;/td&gt;&#xA;          &lt;td&gt;Files and single-page apps served from a folder, with index files and a fallback to &lt;code&gt;index.html&lt;/code&gt;&lt;/td&gt;&#xA;          &lt;td&gt;A rule&amp;rsquo;s action&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Compress&lt;/td&gt;&#xA;          &lt;td&gt;gzip and zstd compression, chosen by what the client accepts&lt;/td&gt;&#xA;          &lt;td&gt;The response&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Cache&lt;/td&gt;&#xA;          &lt;td&gt;Responses that say they can be cached, kept in memory or on disk, with purge by path prefix&lt;/td&gt;&#xA;          &lt;td&gt;Around the backend call&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Limit&lt;/td&gt;&#xA;          &lt;td&gt;Request and connection limits per client address, per rule or per site&lt;/td&gt;&#xA;          &lt;td&gt;Before routing&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Auth&lt;/td&gt;&#xA;          &lt;td&gt;API keys, basic auth, or the check handed to an identity service&lt;/td&gt;&#xA;          &lt;td&gt;Before routing&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Split&lt;/td&gt;&#xA;          &lt;td&gt;Weighted and canary splits between pools, by percentage or by header&lt;/td&gt;&#xA;          &lt;td&gt;A rule&amp;rsquo;s action&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Guard&lt;/td&gt;&#xA;          &lt;td&gt;Watches proxy errors after an apply, and rolls the change back by itself if they jump&lt;/td&gt;&#xA;          &lt;td&gt;Config changes&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Export&lt;/td&gt;&#xA;          &lt;td&gt;Request records sent to OpenTelemetry and log stores&lt;/td&gt;&#xA;          &lt;td&gt;The record&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;BareProxy Fleet&lt;/td&gt;&#xA;          &lt;td&gt;One plan applied across many instances, with shared history and request search&lt;/td&gt;&#xA;          &lt;td&gt;Config changes and records&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;rules-every-module-follows&#34;&gt;Rules Every Module Follows&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;The core never depends on a module.&lt;/strong&gt; Take any module out and the core still builds and passes all of its tests.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Fixed plug-in points.&lt;/strong&gt; A module hooks in before routing, as a rule&amp;rsquo;s action, around the backend call, on the response, on the record or on config changes. It can&amp;rsquo;t change how the core matches requests.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;The core&amp;rsquo;s promises still hold.&lt;/strong&gt; A module&amp;rsquo;s config lines are checked before they go live. &lt;code&gt;explain&lt;/code&gt; shows what the module did to a request, &lt;code&gt;plan&lt;/code&gt; reports what a change to its settings affects, and every request it touches still leaves exactly one record.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;A budget of its own.&lt;/strong&gt; Each module stays under 1,500 lines of Go and goes through the same tests as the core.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-modules-look-like-in-a-config&#34;&gt;What Modules Look Like in a Config&lt;/h2&gt;&#xA;&lt;p&gt;Each module adds a few lines of its own. Here Limit and Compress apply to the whole site, Static and Split are rule actions, and Cache sits on a pool:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Roadmap</title>
      <link>https://bareproxy.com/roadmap/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/roadmap/</guid>
      <description>&lt;p&gt;BareProxy goes from a bare core to a platform one step at a time. Each step ships when its tests pass and its numbers are measured.&lt;/p&gt;&#xA;&lt;div style=&#34;overflow-x:auto&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Stage&lt;/th&gt;&#xA;          &lt;th&gt;What it brings&lt;/th&gt;&#xA;          &lt;th&gt;Status&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;0.1 Alpha&lt;/td&gt;&#xA;          &lt;td&gt;BareProxy Core and nine add-on modules; &lt;code&gt;explain&lt;/code&gt;, &lt;code&gt;plan&lt;/code&gt; and &lt;code&gt;why&lt;/code&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Now&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;0.2 Beta&lt;/td&gt;&#xA;          &lt;td&gt;Pilots on real traffic; speed and memory measured against nginx with the same routes&lt;/td&gt;&#xA;          &lt;td&gt;Next&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;0.3&lt;/td&gt;&#xA;          &lt;td&gt;HTTP/2 to backends, and with it gRPC; the PROXY protocol from load balancers in front&lt;/td&gt;&#xA;          &lt;td&gt;Planned&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;0.4&lt;/td&gt;&#xA;          &lt;td&gt;BareProxy Fleet for many instances; Guard switched on by default&lt;/td&gt;&#xA;          &lt;td&gt;Planned&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;1.0&lt;/td&gt;&#xA;          &lt;td&gt;License chosen and first public release&lt;/td&gt;&#xA;          &lt;td&gt;Planned&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;what-stays-fixed&#34;&gt;What Stays Fixed&lt;/h2&gt;&#xA;&lt;p&gt;Every stage keeps the core&amp;rsquo;s rules. The core stays under its 5,000-line budget, matchers stay exact values, prefixes or sets, and a bad config never replaces a good one. New features arrive as modules unless every site needs them.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Platform</title>
      <link>https://bareproxy.com/platform/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://bareproxy.com/platform/</guid>
      <description>&lt;p&gt;BareProxy is a bare core with add-on modules around it. The core does six things and stops there. Modules add the rest, one at a time, and the core needs none of them.&lt;/p&gt;&#xA;&lt;h2 id=&#34;bareproxy-core&#34;&gt;BareProxy Core&lt;/h2&gt;&#xA;&lt;div style=&#34;overflow-x:auto&#34;&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;What it does&lt;/th&gt;&#xA;          &lt;th&gt;How&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Reverse proxy&lt;/td&gt;&#xA;          &lt;td&gt;HTTP/1.1 and HTTP/2 from clients, HTTP/1.1 to backends. WebSocket and streamed responses pass straight through.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;TLS&lt;/td&gt;&#xA;          &lt;td&gt;Certificates from Let&amp;rsquo;s Encrypt or any ACME CA, obtained and renewed on their own, or loaded from files. TLS 1.2 minimum.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Routing&lt;/td&gt;&#xA;          &lt;td&gt;By host name, exact path or path prefix, method and header. The first matching rule wins.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Backend health&lt;/td&gt;&#xA;          &lt;td&gt;Active checks plus failure counting on live traffic. Requests go to the healthy backend with the fewest requests in flight.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Config changes&lt;/td&gt;&#xA;          &lt;td&gt;A new config is checked in full, then swapped in at once. Requests in flight finish on the old one, removed backends drain, and one command rolls back.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Request tracing&lt;/td&gt;&#xA;          &lt;td&gt;Every request gets an ID and leaves one record. &lt;code&gt;why&lt;/code&gt;, &lt;code&gt;tail&lt;/code&gt;, &lt;code&gt;explain&lt;/code&gt; and &lt;code&gt;plan&lt;/code&gt; read them.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;design-rules&#34;&gt;Design Rules&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;strong&gt;Match on what you forward.&lt;/strong&gt; The path is normalized once, routed on, and sent to the backend in that same form.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;First match wins.&lt;/strong&gt; Rules are read from the top. There is no precedence order to learn.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Matchers are exact values, prefixes or sets.&lt;/strong&gt; No regular expressions, no variables, no scripting. That is what lets &lt;code&gt;plan&lt;/code&gt; say exactly which requests a change affects.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;A bad config never replaces a good one.&lt;/strong&gt; Every config is checked in full on apply, on reload and at startup.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;One record per request,&lt;/strong&gt; and any record can be explained.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Nothing from outside the Go project.&lt;/strong&gt; Go&amp;rsquo;s standard library and the Go team&amp;rsquo;s own packages, and nothing else.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;how-a-request-is-handled&#34;&gt;How a Request Is Handled&lt;/h2&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;The connection arrives, and the TLS handshake picks the certificate and HTTP/1.1 or HTTP/2.&lt;/li&gt;&#xA;&lt;li&gt;BareProxy gives the request an ID, checks it and normalizes its path.&lt;/li&gt;&#xA;&lt;li&gt;The host picks the site, and the site&amp;rsquo;s rules are tried from the top.&lt;/li&gt;&#xA;&lt;li&gt;The rule answers directly, redirects, or names a pool.&lt;/li&gt;&#xA;&lt;li&gt;The pool picks the backend with the fewest requests in flight, and BareProxy forwards a fresh request to it, with one retry if the connection can&amp;rsquo;t be opened.&lt;/li&gt;&#xA;&lt;li&gt;The response streams back, and the request&amp;rsquo;s record is written.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The config behind all this fits on one page. &lt;a href=&#34;https://bareproxy.com/config/&#34;&gt;The config reference&lt;/a&gt; has a complete example, and &lt;a href=&#34;https://bareproxy.com/modules/&#34;&gt;the modules&lt;/a&gt; page shows where each add-on plugs in.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
