BareProxy Is a Small Go Web Server and Reverse Proxy That Explains Every Routing Decision
Most sites use a thin slice of nginx: TLS, a folder of static files, a couple of routes to an app, health checks and the odd reload. The config grows anyway, one regex at a time, until nobody is quite sure which block handles a given URL.
BareProxy keeps its core to that slice and makes it answer questions. bareproxy explain takes a URL and shows which rule matched, which file or backend would serve it, and why the rules above it didn’t match. bareproxy why tells the story of a request that already happened, starting from the ID it carried in a response header.
The interesting one is bareproxy plan. Before a config goes live, it compares the new file with the running one and lists the requests that would change hands. A rule that can never match, because an earlier rule takes all its traffic, gets a warning. This works because the config has no regular expressions and no scripting. Every matcher is an exact value, a prefix or a set, so the requests a site can get fall into a finite number of classes, and BareProxy can check each one.
For static sites the core serves a folder directly, with certificates from Let’s Encrypt, so a Hugo build needs no second server in front of it. Caching, rate limits and the rest are modules, compiled in only when you want them.
BareProxy is at version 0.1. The numbers on the site are design budgets, such as under 5,000 lines of Go in the core and no dependencies from outside the Go project, and speed and memory against nginx get measured next. The demo page shows each command’s output on a sample config.