Expand description
Reverse proxy with HTTP routing for containers and Wasm trigger dispatch.
Routes HTTP traffic by Host header to container backends (round-robin),
and by path pattern to Wasm component invocations via a callback.
Supports automatic TLS via ACME/Let’s Encrypt (Caddy-style zero-config).
Modules§
- acme
- ACME certificate management with automatic Let’s Encrypt provisioning.
- rate_
limit - Simple per-IP token bucket rate limiter.
- sni
- Peek at TLS ClientHello to extract SNI hostname without consuming bytes.
- tls
- TLS configuration for the reverse proxy.
Structs§
- Fallback
Config - Fallback proxy configuration. When orca’s route table has no match, requests are forwarded here. Lets orca coexist with another reverse proxy.
- Route
Target - A backend target for container routing.
- Security
Headers Config - Security response headers the proxy adds to every response it returns —
add-if-absent, so a backend that sets its own
Content-Security-Policy,X-Frame-Options,Strict-Transport-Security, etc. is never overridden (pass-through-plus-defaults, as Traefik/Caddy do). HSTS is applied only to HTTPS responses. The defaults are deliberately non-breaking;X-Frame-Optionsand CSP are off by default (they break iframe-embedded apps and most apps respectively) and are opt-in here or per app. - Wasm
Trigger - A Wasm HTTP trigger: maps a path pattern to a Wasm runtime instance.
Functions§
- init_
security_ headers - Install the proxy’s security-header policy (call once at startup). See
[
security_headers]. Install the proxy’s security-header policy from config. Call once at startup before serving.Noneinstalls the safe default set (on); a disabled config installs an empty (no-op) policy. - run_
proxy - Run the reverse proxy on the given port.
- run_
proxy_ with_ acme - Run HTTP on port 80 (for ACME challenges + redirect) and HTTPS on port 443.
- run_
proxy_ with_ acme_ and_ fallback - Run HTTP+HTTPS with ACME and optional fallback to another reverse proxy.
- run_
proxy_ with_ fallback - Run the proxy with optional fallback support.
Type Aliases§
- Shared
Cert Resolver - Shared dynamic cert resolver for hot-provisioning.
- Shared
Wasm Triggers - Shared Wasm trigger table type.
- Wasm
Invoke Future - Future type returned by the Wasm invoker.
- Wasm
Invoker - Callback invoked when a request matches a Wasm trigger. Receives (runtime_id, method, path, body) and returns the response body string.