1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
// SPDX-License-Identifier: Apache-2.0
// Copyright (c) 2024 Praxis Contributors
//! Protocol adapters for Praxis.
//!
//! `praxis-protocol` sits below `server` and above `filter` in the
//! crate dependency flow `server -> protocol -> filter -> core -> tls`.
//! It binds the [`praxis_filter`] pipeline engine to Pingora's HTTP and
//! TCP proxy services, so that inbound connections are served, filters
//! run at the right lifecycle points, and requests are forwarded to
//! upstream clusters.
//!
//! Responsibilities:
//! - HTTP protocol implementations and Pingora adapters ([`http`]).
//! - Raw TCP/L4 forwarding ([`tcp`]).
//! - Active health-check probes and admin/observability endpoints.
//! - TLS listener setup (the `tls_setup` module) and keeping certificate hot-reload watchers alive for the process
//! lifetime ([`CertWatcherShutdowns`]).
//!
//! Boundary with Pingora: Pingora owns request-smuggling prevention,
//! HTTP/2 backpressure, connection-pool safety, and HTTP/1.1 upgrade
//! detection with bidirectional forwarding (WebSocket and similar).
//! Praxis code in this crate and in [`praxis_filter`] owns hop-by-hop
//! header stripping (with conditional preservation for upgrade
//! requests), Host validation, `X-Forwarded-*` injection, and retry
//! logic.
use ;
use watch;
pub use ListenerPipelines;
/// Process-wide connection limit.
/// HTTP protocol implementations.
/// Raw TCP/L4 forwarding protocol.
/// Shared TLS settings builder for HTTP and TCP listeners.
pub
// -----------------------------------------------------------------------------
// CertWatcherShutdowns
// -----------------------------------------------------------------------------
/// Collected TLS certificate watcher shutdown senders.
///
/// Keeps [`watch::Sender`]s alive so that background [`CertWatcher`]
/// tasks run until the process exits. Dropping these senders signals
/// the watchers to stop.
///
/// [`watch::Sender`]: tokio::sync::watch::Sender
/// [`CertWatcher`]: praxis_tls::watcher::CertWatcher
// -----------------------------------------------------------------------------
// Protocol
// -----------------------------------------------------------------------------
/// A protocol implementation that registers services onto a shared server runtime.