Expand description
ferryman-edge — programmable mTLS L7 reverse proxy pipeline.
inbound TCP
-> TlsAcceptor::accept using the current ReloadingTls config
-> hyper serve_connection over the TLS stream
-> per-request: JWT verify, rate-limit by Claims::sub, route, proxy
main.rs is arg parsing + boot; this crate root owns the accept loop
(serve) and the auth middleware in front of proxy::handle, so both
can be driven directly from an integration test without a real process.
Most users want the ferryman-edge-server binary (cargo install ferryman-edge). This library API exists for that binary and its tests
and is not yet semver-stable; the reusable primitives live in
ferryman-edge-core.
Modules§
- proxy
- Per-request handler. Looks up the routing table, rebuilds the URI for the chosen upstream, strips hop-by-hop headers, forwards via the shared hyper client, records metrics, and turns transport errors / 502-504 into circuit-breaker trips.
- reload
- SIGUSR1-driven routing-table reload.
Structs§
- AppState
- Everything a connection/request needs, built once at boot.
Functions§
- serve
- Accept loop. Runs until
shutdownresolves, then stops accepting new connections, lets in-flight ones finish (bounded bySHUTDOWN_DRAIN), and returns.
Type Aliases§
- Upstream
Client - Shared upstream client. One instance for the whole process — its internal pool multiplexes HTTP/2 streams to each upstream.