About
BareProxy is a project at an early stage. It asks how little machinery it takes to provide the part of nginx that most applications use, and answers with a bare core and a set of add-on modules around it. Version 0.1 is an Alpha. This site shows where the project stands.
Why the Project Exists
Most applications use a small part of nginx. They need TLS, routing by host name and path, requests spread over backends that are actually up, config changes that don’t drop traffic, and a way to find out what happened to a request when something breaks. The proxies that do this well carry decades of features most sites never touch. Each of those features is code that runs at the edge, in front of everything else.
Two events made the project worth starting. Cloudflare’s outages of 18 November and 5 December 2025 both began with a config change that reached every server within seconds. Then in May 2026, NGINX Rift showed that a heap overflow had sat in nginx’s rewrite module since 2008. BareProxy’s answer to both is less machinery. Every config is checked in full before it can go live, the code is memory-safe Go, and there is no regex rewrite engine to get wrong.
What the Project Is Building
- BareProxy Core. TLS, routing, backend health, live config changes and request tracing, in one binary with a published budget of 5,000 lines of Go. The platform
- Nine add-on modules. Static files, compression, caching, rate limits, access checks, traffic splits, guarded applies, record export and fleets. Each one is optional, and the core needs none of them. The modules
- Tools that explain.
whytells the story of any request,explainshows how a request would be handled, andplansays what a config change will do before it goes live. See them at work
How the Project Works
- Small by default. A feature that doesn’t fit the core’s budget becomes a module, or waits.
- Explain everything. Every request leaves one record, and every decision can be explained by the same code that made it.
- Measure, then say it. Speed and memory are measured against nginx with the same routes, and published with the commands that reproduce them. Until then, numbers on this site are design budgets and say so.
License and Availability
BareProxy is not public yet. The license will be chosen before the first public release. Until then the code is marked “all rights reserved”, and the demo is the way to see it work.