{"id":39086060,"url":"https://github.com/mucahitkurtlar/sret","last_synced_at":"2026-01-17T18:39:36.660Z","repository":{"id":305768947,"uuid":"1021777849","full_name":"mucahitkurtlar/sret","owner":"mucahitkurtlar","description":"A Rust reverse proxy with HTTPS/TLS, advanced routing, load balancing, response caching, and health monitoring","archived":false,"fork":false,"pushed_at":"2025-07-28T22:14:47.000Z","size":121,"stargazers_count":1,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"master","last_synced_at":"2025-07-28T23:22:07.065Z","etag":null,"topics":["gateway","https","hyper","load-balancer","reverse-proxy","rust","ssl","tls","tokio"],"latest_commit_sha":null,"homepage":"","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mucahitkurtlar.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-07-18T00:05:21.000Z","updated_at":"2025-07-28T22:10:37.000Z","dependencies_parsed_at":"2025-07-21T23:30:36.335Z","dependency_job_id":null,"html_url":"https://github.com/mucahitkurtlar/sret","commit_stats":null,"previous_names":["mucahitkurtlar/sret"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/mucahitkurtlar/sret","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mucahitkurtlar%2Fsret","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mucahitkurtlar%2Fsret/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mucahitkurtlar%2Fsret/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mucahitkurtlar%2Fsret/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mucahitkurtlar","download_url":"https://codeload.github.com/mucahitkurtlar/sret/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mucahitkurtlar%2Fsret/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28516198,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-17T18:28:00.501Z","status":"ssl_error","status_checked_at":"2026-01-17T18:28:00.150Z","response_time":85,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["gateway","https","hyper","load-balancer","reverse-proxy","rust","ssl","tls","tokio"],"created_at":"2026-01-17T18:39:36.207Z","updated_at":"2026-01-17T18:39:36.642Z","avatar_url":"https://github.com/mucahitkurtlar.png","language":"Rust","funding_links":[],"categories":[],"sub_categories":[],"readme":"# sret\n\nsret is a Layer 7 reverse proxy written in Rust, featuring advanced routing, load balancing, HTTPS/TLS termination, response caching, and comprehensive health monitoring.\n\n## Features\n\n- **Multi-Server Architecture**: Configure multiple proxy servers with different routing rules\n- **HTTPS/TLS Support**: Optional SSL/TLS termination with certificate configuration\n- **Advanced Routing**: Domain and path-based routing with flexible matching\n- **Load Balancing**: Four algorithms (Round Robin, Least Connections, Random, Weighted Round Robin)\n- **HTTP Response Caching**: In-memory caching with TTL and LRU eviction (partially implemented)\n- **Health Monitoring**: Automatic upstream health checking with configurable intervals\n- **Path Rewriting**: Automatic path prefix stripping for clean backend requests\n- **Configuration-Driven**: YAML-based configuration with validation\n- **High Performance**: Built with Tokio and modern async Rust patterns\n- **Comprehensive Testing**: Thoroughly tested across unit, integration, and performance scenarios\n\n## Quick Start\n\n### Installation\n\n1. Clone the repository:\n\n```bash\ngit clone https://github.com/mucahitkurtlar/sret.git\ncd sret\n```\n\n2. Build the project:\n\n```bash\ncargo build --release\n```\n\n3. Run with default configuration:\n\n```bash\n./target/release/sret --config config.yaml\n```\n\n### Configuration\n\nCreate a `config.yaml` file:\n\n```yaml\nupstreams:\n  - id: \"backend\"\n    targets:\n      - host: \"127.0.0.1\"\n        port: 8080\n        weight: 1\n        health_check_path: \"/health\"\n      - host: \"127.0.0.1\"\n        port: 8081\n        weight: 2\n        health_check_path: \"/health\"\n    strategy: \"RoundRobin\"\n    health_check:\n      interval_seconds: 30\n      timeout_seconds: 5\n      expected_status: 200\n  - id: \"console\"\n    targets:\n      - host: \"127.0.0.1\"\n        port: 3000\n  - id: \"ui\"\n    targets:\n      - host: \"127.0.0.1\"\n        port: 3001\n\nservers:\n  - id: \"main\"\n    bind_address: \"0.0.0.0\"\n    port: 80\n    routes:\n      - domains:\n          - \"api.home.arpa\"\n          - \"service.home.arpa\"\n        paths:\n          - \"/api\"\n          - \"/service\"\n        upstream: \"backend\"\n\n      - domains:\n          - \"console.home.arpa\"\n        paths:\n          - \"/console\"\n        upstream: \"console\"\n\n      - domains:\n          - \"ui.home.arpa\"\n          - \"dashboard.home.arpa\"\n        paths:\n          - \"/ui\"\n          - \"/dashboard\"\n        upstream: \"ui\"\n    cache:\n      max_size: 1000\n      default_ttl_seconds: 10\n```\n\n## Architecture\n\n### Multi-Server Design\n\nsret supports multiple proxy servers, each with their own:\n\n- **Bind Address \u0026 Port**: Independent network endpoints\n- **Routing Rules**: Domain and path-based request matching\n- **Upstream Associations**: Flexible backend server groups\n\n### Advanced Routing\n\n**Domain-Based Routing**: Route requests based on the Host header\n\n```yaml\nroutes:\n  - domains: [\"api.example.com\", \"service.example.com\"]\n    upstream: \"backend\"\n```\n\n**Path-Based Routing**: Route requests based on URL paths with automatic prefix stripping\n\n```yaml\nroutes:\n  - paths: [\"/api\", \"/v1\"]\n    upstream: \"backend\"\n    # Request to /api/users becomes /users at backend\n```\n\n**Combined Routing**: Use both domain and path matching for precise control\n\n```yaml\nroutes:\n  - domains: [\"api.example.com\"]\n    paths: [\"/v1\", \"/v2\"]\n    upstream: \"backend\"\n```\n\n### Upstream Management\n\nEach upstream defines a group of target servers with:\n\n- **Load Balancing**: Distribute requests across multiple targets\n- **Health Monitoring**: Automatic health checks and failover\n- **Weighted Distribution**: Control traffic distribution with target weights\n\n## Load Balancing Algorithms\n\nsret supports four load balancing strategies:\n\n### Round Robin\n\nDistributes requests evenly across all available targets in sequence.\n\n```yaml\nstrategy: \"RoundRobin\"\n```\n\n### Least Connections\n\nRoutes requests to the target with the fewest active connections.\n\n```yaml\nstrategy: \"LeastConnections\"\n```\n\n### Random\n\nRandomly selects from available healthy targets.\n\n```yaml\nstrategy: \"Random\"\n```\n\n### Weighted Round Robin\n\nDistributes requests based on target weights, allowing traffic shaping.\n\n```yaml\nstrategy: \"WeightedRoundRobin\"\ntargets:\n  - host: \"127.0.0.1\"\n    port: 8080\n    weight: 3 # Receives 3x more traffic\n  - host: \"127.0.0.1\"\n    port: 8081\n    weight: 1 # Baseline traffic\n```\n\n## Health Checks\n\nsret supports comprehensive health monitoring with automatic failover:\n\n```yaml\nupstreams:\n  - id: \"backend\"\n    health_check:\n      interval_seconds: 30 # Check every 30 seconds\n      timeout_seconds: 5 # 5 second timeout per check\n      expected_status: 200 # Expected HTTP status code\n    targets:\n      - host: \"127.0.0.1\"\n        port: 8080\n        health_check_path: \"/health\" # Per-target health endpoint\n```\n\n**Health Check Behavior**:\n\n- Unhealthy targets are automatically excluded from load balancing\n- Healthy targets are re-added when they recover\n- Health status changes are logged for monitoring\n- Each target can have its own health check endpoint\n\n## HTTPS/TLS Support\n\nsret supports HTTPS with TLS termination using SSL certificates:\n\n```yaml\nservers:\n  - id: \"https-server\"\n    bind_address: \"0.0.0.0\"\n    port: 443\n    tls:\n      cert_path: \"/path/to/certificate.pem\"\n      key_path: \"/path/to/private-key.pem\"\n    routes:\n      - domains: [\"secure.example.com\"]\n        upstream: \"backend\"\n```\n\n**TLS Configuration**:\n\n- **cert_path**: Path to the PEM-encoded certificate file (certificate chain)\n- **key_path**: Path to the PEM-encoded private key file\n- **Protocol Support**: HTTP/1.1 over TLS\n- **Certificate Formats**: PEM format certificates and keys\n\n**Certificate Requirements**:\n\n- Certificates must be in PEM format\n- Private keys must be in PEM format (RSA or ECDSA)\n- Certificate chain should include intermediate certificates if required\n- File paths must be accessible by the sret process\n\n**Mixed HTTP/HTTPS Setup**:\n\nYou can run both HTTP and HTTPS servers simultaneously:\n\n```yaml\nservers:\n  # HTTPS server\n  - id: \"https\"\n    bind_address: \"0.0.0.0\"\n    port: 443\n    tls:\n      cert_path: \"/etc/ssl/certs/example.pem\"\n      key_path: \"/etc/ssl/private/example.key\"\n    routes:\n      - domains: [\"secure.example.com\"]\n        upstream: \"backend\"\n\n  # HTTP server (for redirects or development)\n  - id: \"http\"\n    bind_address: \"0.0.0.0\"\n    port: 80\n    routes:\n      - domains: [\"example.com\"]\n        upstream: \"backend\"\n```\n\n## HTTP Response Caching\n\n\u003e [!WARNING]  \n\u003e This feature is partially implemented and may not be fully functional yet.\n\nsret provides intelligent HTTP response caching to improve performance and reduce upstream load:\n\n```yaml\nservers:\n  - id: \"cached-server\"\n    bind_address: \"127.0.0.1\"\n    port: 8080\n    cache:\n      max_size: 5000 # Store up to 5000 cached responses\n      default_ttl_seconds: 30 # Cache for 30 seconds by default\n    routes:\n      - paths: [\"/api\"]\n        upstream: \"backend\"\n```\n\n**Caching Features**:\n\n- **LRU Eviction**: Least Recently Used cache eviction when max_size is reached\n- **TTL Support**: Time-to-live based expiration with configurable defaults\n- **Cache-Control Respect**: Honors max-age, no-cache, and no-store directives\n- **Cache Metrics**: Built-in hit/miss ratio tracking and cache size monitoring\n\n**Cache Behavior**:\n\n- Only GET and HEAD requests are cached by default\n- Cache keys include HTTP method, host, path, query parameters, and some headers\n- Responses with Cache-Control: no-cache or no-store are never cached\n- Cache entries are automatically expired based on TTL\n- Cache is per-server instance and stored in memory\n\n## Testing\n\nFor detailed testing information, see [TESTING.md](TESTING.md).\n\n## Example Usage\n\n### Basic Multi-Service Proxy\n\n1. Start your backend services:\n\n```bash\n# API Service #1\npython3 -m http.server 8080\n\n# API Service #2\npython3 -m http.server 8081\n\n# Web UI\npython3 -m http.server 3000\n\n# Admin Console\npython3 -m http.server 3001\n```\n\n2. Create `config.yaml`:\n\n```yaml\nupstreams:\n  - id: \"api\"\n    targets:\n      - host: \"127.0.0.1\"\n        port: 8080\n        weight: 1\n        health_check_path: \"/health\"\n\n      - host: \"127.0.0.1\"\n        port: 8081\n        weight: 2\n        health_check_path: \"/health\"\n    strategy: \"WeightedRoundRobin\"\n    health_check:\n      interval_seconds: 30\n      timeout_seconds: 5\n      expected_status: 200\n\n  - id: \"ui\"\n    targets:\n      - host: \"127.0.0.1\"\n        port: 3000\n\n  - id: \"admin\"\n    targets:\n      - host: \"127.0.0.1\"\n        port: 3001\n\nservers:\n  - id: \"main-proxy\"\n    bind_address: \"127.0.0.1\"\n    port: 80\n    routes:\n      - domains: [\"api.home.arpa\"]\n        paths: [\"/api\", \"/v1\"]\n        upstream: \"api\"\n\n      - domains: [\"app.home.arpa\"]\n        upstream: \"ui\"\n\n      - paths: [\"/admin\"]\n        upstream: \"admin\"\n```\n\n3. Start sret:\n\n```bash\n./target/release/sret --config config.yaml\n```\n\n4. Test the routing:\n\n```bash\n# Routes to API service\ncurl -H \"Host: api.localhost\" http://127.0.0.1/api/users\n\n# Routes to UI service\ncurl -H \"Host: app.localhost\" http://127.0.0.1/\n\n# Routes to admin service\ncurl http://127.0.0.1/admin/dashboard\n```\n\n## Configuration Reference\n\n### Complete Configuration Schema\n\n```yaml\nupstreams:\n  - id: \"string\" # Unique upstream identifier\n    targets: # List of backend servers\n      - host: \"string\" # Target hostname/IP\n        port: number # Target port\n        weight: number # Optional: Traffic weight (default: 1)\n        health_check_path: \"string\" # Optional: Health check endpoint\n    strategy: \"string\" # Optional: RoundRobin|LeastConnections|Random|WeightedRoundRobin\n    health_check: # Optional: Health check configuration\n      interval_seconds: number # Check interval (default: 30)\n      timeout_seconds: number # Check timeout (default: 5)\n      expected_status: number # Expected HTTP status (default: 200)\n\nservers:\n  - id: \"string\" # Unique server identifier\n    bind_address: \"string\" # Bind IP address\n    port: number # Listen port\n    tls: # Optional: TLS/HTTPS configuration\n      cert_path: \"string\" # Path to PEM certificate file\n      key_path: \"string\" # Path to PEM private key file\n    cache: # Optional: HTTP response caching configuration\n      max_size: number # Maximum number of cached responses\n      default_ttl_seconds: number # Default cache TTL in seconds\n    routes: # List of routing rules\n      - domains: [\"string\"] # Optional: Domain matching\n        paths: [\"string\"] # Optional: Path prefix matching\n        upstream: \"string\" # Target upstream ID\n```\n\n### Configuration Validation\n\nsret validates configuration on startup and will report:\n\n- Missing required fields\n- Invalid upstream references\n- Duplicate server IDs\n- Invalid load balancing strategies\n- Port conflicts\n\n## Command Line Usage\n\n```bash\nsret [OPTIONS]\n\nOptions:\n  -c, --config \u003cFILE\u003e    Configuration file path [default: config.yaml]\n  -h, --help             Print help information\n```\n\n## Development\n\n### Building from Source\n\n```bash\ngit clone https://github.com/mucahitkurtlar/sret.git\ncd sret\ncargo build --release\n```\n\n### Running Tests\n\nSee [TESTING.md](TESTING.md) for detailed test instructions.\n\n## License\n\nThis project is licensed under the GPL-3.0 License - see the [LICENSE](LICENSE) file for details.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmucahitkurtlar%2Fsret","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmucahitkurtlar%2Fsret","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmucahitkurtlar%2Fsret/lists"}