Skip to main content

Crate ferryman_edge_core

Crate ferryman_edge_core 

Source
Expand description

ferryman-edge-core — programmable mTLS L7 proxy primitives.

Extends ferryman-core (P2) with:

  • tls : rustls 0.23 + aws-lc-rs mTLS server config + ReloadingTls that swaps cert/key/ca on SIGUSR1 without dropping live connections.
  • jwt : JwtVerifier with a moka LRU cache (default 10k entries, 5 min TTL) keyed by the raw token string.
  • ratelimit: keyed governor GCRA limiter; allocation-free on the hot path.
  • route : the P2 routing table (Upstream, RouteTable, SharedTable). Copied verbatim — P4 layers atop, does not modify.
  • health : active probe loop (copied from P2).
  • config : TOML schema extended with tls, jwks_path, per-tenant rate-limit caps.

The server crate composes these behind a tokio-rustls acceptor and a hyper service.

Re-exports§

pub use config::build_table;
pub use config::ConfigToml;
pub use config::JwtToml;
pub use config::RouteToml;
pub use config::TlsToml;
pub use health::health_loop;
pub use jwt::Claims;
pub use jwt::JwtVerifier;
pub use ratelimit::build_limiter;
pub use ratelimit::check;
pub use ratelimit::spawn_gc;
pub use ratelimit::Limiter;
pub use route::RouteTable;
pub use route::SharedTable;
pub use route::Upstream;
pub use tls::build_mtls_config;
pub use tls::ReloadingTls;

Modules§

config
TOML config schema for ferryman-edge.
health
Active health checker. Probes every upstream’s /health on a fixed interval; flips the circuit breaker (Upstream::mark_success / mark_failed) and emits the ferryman_upstream_alive gauge.
jwt
JWT verification with an in-memory cache.
ratelimit
Per-tenant rate limiter using governor’s GCRA (Generic Cell Rate Algorithm). Keyed by Claims::sub after JWT verification.
route
Routing table + per-upstream circuit breaker.
tls
mTLS server config + hot-reloading wrapper.