Skip to main content

Crate ferryman_edge

Crate ferryman_edge 

Source
Expand description

ferryman-edge — programmable mTLS L7 reverse proxy pipeline.

inbound TCP -> TlsAcceptor::accept using the current ReloadingTls config -> hyper serve_connection over the TLS stream -> per-request: JWT verify, rate-limit by Claims::sub, route, proxy

main.rs is arg parsing + boot; this crate root owns the accept loop (serve) and the auth middleware in front of proxy::handle, so both can be driven directly from an integration test without a real process.

Most users want the ferryman-edge-server binary (cargo install ferryman-edge). This library API exists for that binary and its tests and is not yet semver-stable; the reusable primitives live in ferryman-edge-core.

Modules§

proxy
Per-request handler. Looks up the routing table, rebuilds the URI for the chosen upstream, strips hop-by-hop headers, forwards via the shared hyper client, records metrics, and turns transport errors / 502-504 into circuit-breaker trips.
reload
SIGUSR1-driven routing-table reload.

Structs§

AppState
Everything a connection/request needs, built once at boot.

Functions§

serve
Accept loop. Runs until shutdown resolves, then stops accepting new connections, lets in-flight ones finish (bounded by SHUTDOWN_DRAIN), and returns.

Type Aliases§

UpstreamClient
Shared upstream client. One instance for the whole process — its internal pool multiplexes HTTP/2 streams to each upstream.