{"id":34646873,"url":"https://github.com/raskell-io/sentinel","last_synced_at":"2026-02-15T22:16:03.140Z","repository":{"id":330310291,"uuid":"1121540314","full_name":"raskell-io/sentinel","owner":"raskell-io","description":"A security-first reverse proxy built to guard the free web.","archived":false,"fork":false,"pushed_at":"2026-01-10T22:02:06.000Z","size":12816,"stargazers_count":8,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"main","last_synced_at":"2026-01-11T02:36:04.405Z","etag":null,"topics":["gateway","pingora","proxy","rust"],"latest_commit_sha":null,"homepage":"https://sentinel.raskell.io","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/raskell-io.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"docs/AGENTS.md","dco":null,"cla":null}},"created_at":"2025-12-23T06:42:16.000Z","updated_at":"2026-01-10T22:02:09.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/raskell-io/sentinel","commit_stats":null,"previous_names":["raskell-io/sentinel"],"tags_count":32,"template":false,"template_full_name":null,"purl":"pkg:github/raskell-io/sentinel","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/raskell-io%2Fsentinel","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/raskell-io%2Fsentinel/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/raskell-io%2Fsentinel/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/raskell-io%2Fsentinel/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/raskell-io","download_url":"https://codeload.github.com/raskell-io/sentinel/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/raskell-io%2Fsentinel/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28481910,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-16T11:59:17.896Z","status":"ssl_error","status_checked_at":"2026-01-16T11:55:55.838Z","response_time":107,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["gateway","pingora","proxy","rust"],"created_at":"2025-12-24T17:47:42.683Z","updated_at":"2026-02-04T21:06:38.838Z","avatar_url":"https://github.com/raskell-io.png","language":"Rust","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n\n\u003ch1 align=\"center\"\u003e\n  \u003cimg src=\".github/static/sentinel-mascot.png\" alt=\"sentinel mascot\" width=\"96\" /\u003e\n  \u003cbr\u003e\n  Sentinel\n\u003c/h1\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003cem\u003eA security-first reverse proxy built to guard the free web.\u003c/em\u003e\u003cbr\u003e\n  \u003cem\u003eSleepable ops at the edge.\u003c/em\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://www.rust-lang.org/\"\u003e\n    \u003cimg alt=\"Rust\" src=\"https://img.shields.io/badge/Rust-stable-000000?logo=rust\u0026logoColor=white\u0026style=for-the-badge\"\u003e\n  \u003c/a\u003e\n  \u003ca href=\"https://github.com/cloudflare/pingora\"\u003e\n    \u003cimg alt=\"Pingora\" src=\"https://img.shields.io/badge/Built%20on-Pingora-f5a97f?style=for-the-badge\"\u003e\n  \u003c/a\u003e\n  \u003ca href=\"LICENSE\"\u003e\n    \u003cimg alt=\"License\" src=\"https://img.shields.io/badge/License-Apache--2.0-c6a0f6?style=for-the-badge\"\u003e\n  \u003c/a\u003e\n\u003c/p\u003e\n\n\u003cp align=\"center\"\u003e\n  \u003ca href=\"https://sentinel.raskell.io/docs/\"\u003eDocumentation\u003c/a\u003e •\n  \u003ca href=\"https://sentinel.raskell.io/playground/\"\u003ePlayground\u003c/a\u003e •\n  \u003ca href=\"https://sentinel.raskell.io/benchmarks/\"\u003eBenchmarks\u003c/a\u003e •\n  \u003ca href=\"https://github.com/raskell-io/sentinel/discussions\"\u003eDiscussions\u003c/a\u003e •\n  \u003ca href=\"CONTRIBUTING.md\"\u003eContributing\u003c/a\u003e\n\u003c/p\u003e\n\n\u003c/div\u003e\n\n---\n\nSentinel is a high-performance reverse proxy built on [Cloudflare Pingora](https://github.com/cloudflare/pingora). It provides explicit limits, predictable behavior, and production-grade defaults for environments where operators need to sleep.\n\n**Performance:** Lowest p99 latency in [benchmarks](https://sentinel.raskell.io/benchmarks/) against Envoy, HAProxy, Nginx, and Caddy. 1M-request soak tests with 99.95% success rate and zero memory leaks. Pure Rust WAF engine processes clean traffic at 912K req/s — 30x faster than the C++ ModSecurity reference.\n\n## Status\n\nProduction-ready core (proxy, routing, TLS, caching, load balancing). Agents are individually versioned — WAF, Auth, and AI Gateway are stable; others are beta or alpha. See [sentinel.raskell.io/agents](https://sentinel.raskell.io/agents/) for per-agent status.\n\n## Quick Start\n\n```bash\n# Install\ncurl -fsSL https://getsentinel.raskell.io | sh\n\n# Or via Cargo\ncargo install sentinel-proxy\n\n# Or via Docker\ndocker run -v $(pwd)/sentinel.kdl:/etc/sentinel/sentinel.kdl \\\n  ghcr.io/raskell-io/sentinel --config /etc/sentinel/sentinel.kdl\n```\n\nSave this as `sentinel.kdl` — it proxies `localhost:8080` to a backend on port `8081`:\n\n```kdl\nsystem {\n    worker-threads 0  // auto-detect CPU cores\n}\n\nlisteners {\n    listener \"http\" {\n        address \"0.0.0.0:8080\"\n        protocol \"http\"\n    }\n}\n\nroutes {\n    route \"default\" {\n        matches {\n            path-prefix \"/\"\n        }\n        upstream \"backend\"\n    }\n}\n\nupstreams {\n    upstream \"backend\" {\n        target \"127.0.0.1:8081\"\n    }\n}\n```\n\n```bash\n# Run\nsentinel --config sentinel.kdl\n\n# Validate config without starting\nsentinel test --config sentinel.kdl\n```\n\nMore examples: [`config/examples/`](config/examples/) covers API gateways, load balancing, WebSocket, caching, inference routing, and more. Or use the [config builder](https://sentinel.raskell.io/customize/) to generate a config interactively.\n\n## Features\n\n| Feature | Description |\n|---------|-------------|\n| **Service Types** | Web, API, Static, Builtin, and Inference (LLM/AI) |\n| **Load Balancing** | 14 algorithms: round-robin, weighted, least connections, Maglev, Peak EWMA, and more |\n| **Security** | TLS/mTLS, rate limiting, GeoIP filtering, WAF, zip bomb protection |\n| **Agent Protocol** | External agents for WAF, auth, and custom logic — crash-isolated, any language |\n| **HTTP Caching** | Pingora-based response caching with stampede prevention and S3-FIFO + TinyLFU eviction |\n| **WebSocket Proxying** | RFC 6455 compliant with frame inspection and traffic mirroring |\n| **Observability** | Prometheus metrics, structured logging, OpenTelemetry tracing |\n| **Hot Reload** | Zero-downtime config updates via SIGHUP with validation and atomic swap |\n\nSee the full feature breakdown at [sentinel.raskell.io/features](https://sentinel.raskell.io/features/).\n\n### Use Cases\n\n- **Reverse Proxy** — TLS termination, static file serving, compression, and security headers for web applications\n- **API Gateway** — Versioned routing, JWT/API key auth, per-client rate limiting, and JSON error responses\n- **Load Balancer** — Weighted traffic distribution, health checks, circuit breakers, and blue-green/canary deployments\n- **Inference Gateway** — Token-based rate limiting, model routing with glob patterns (`gpt-4*`, `claude-*`), prompt injection detection, and PII filtering for OpenAI, Anthropic, and generic LLM providers\n- **WebSocket Gateway** — Persistent connection proxying with frame inspection, message rate limiting, and session affinity\n- **Security Gateway** — WAF, GeoIP filtering, mTLS, and composable agent pipelines for custom security logic\n\nExample configs for each: [`config/examples/`](config/examples/)\n\n## Why Sentinel\n\nModern proxies accumulate hidden behavior, unbounded complexity, and operational risk that surfaces under stress. Sentinel takes a different approach:\n\n- **Bounded resources** — Memory limits, queue depths, deterministic timeouts. No surprise behavior.\n- **Explicit failure modes** — Fail-open or fail-closed per route, never ambiguous.\n- **External extensibility** — Security logic lives in agents, not the core. Small, stable dataplane.\n- **Observable by default** — Every decision is logged and metered. Features ship only when bounded, observed, and tested.\n\nThe goal is infrastructure that is **correct, calm, and trustworthy**. See [`MANIFESTO.md`](MANIFESTO.md) for the full philosophy.\n\n## Agents\n\nSentinel's security and extensibility lives in **agents** — external processes that hook into every request phase. Agents are crash-isolated from the proxy, independently deployable, and can be written in any language.\n\nAgent SDKs: [Rust](https://github.com/raskell-io/sentinel-agent-rust-sdk) · [Go](https://github.com/raskell-io/sentinel-agent-go-sdk) · [Python](https://github.com/raskell-io/sentinel-agent-python-sdk) · [TypeScript](https://github.com/raskell-io/sentinel-agent-typescript-sdk) · [Elixir](https://github.com/raskell-io/sentinel-agent-elixir-sdk) · [Kotlin](https://github.com/raskell-io/sentinel-agent-kotlin-sdk) · [Haskell](https://github.com/raskell-io/sentinel-agent-haskell-sdk)\n\n| Agent | Description |\n|-------|-------------|\n| [WAF](https://github.com/raskell-io/sentinel-agent-waf) | Pure Rust WAF — 200+ detection rules, ML-powered anomaly scoring, zero C dependencies |\n| [AI Gateway](https://github.com/raskell-io/sentinel-agent-ai-gateway) | Prompt injection detection, jailbreak prevention, PII filtering for LLM APIs |\n| [Policy](https://github.com/raskell-io/sentinel-agent-policy) | Multi-engine policy evaluation (Rego/OPA and Cedar) — written in Haskell |\n| [Auth](https://github.com/raskell-io/sentinel-agent-auth) | JWT, OIDC, SAML, mTLS, API keys with Cedar-based fine-grained authorization |\n| [Chaos](https://github.com/raskell-io/sentinel-agent-chaos) | Latency injection, error simulation, connection resets with safety guardrails |\n| [Lua](https://github.com/raskell-io/sentinel-agent-lua) | Sandboxed Lua scripting with VM pooling, hot-reload, and resource limits |\n| [SentinelSec](https://github.com/raskell-io/sentinel-agent-sentinelsec) | Pure Rust ModSecurity — OWASP CRS-compatible SecLang parser, zero C dependencies |\n| [WebSocket Inspector](https://github.com/raskell-io/sentinel-agent-websocket-inspector) | Content filtering, JSON/MessagePack validation, and rate limiting for WebSocket frames |\n| [MQTT Gateway](https://github.com/raskell-io/sentinel-agent-mqtt-gateway) | IoT protocol security with topic ACLs, auth, and payload inspection |\n\nBrowse all 25+ agents at [sentinel.raskell.io/agents](https://sentinel.raskell.io/agents/).\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eCrates\u003c/strong\u003e\u003c/summary\u003e\n\nEach crate has its own `docs/` directory with detailed documentation.\n\n| Crate | Description |\n|-------|-------------|\n| [`sentinel-proxy`](crates/proxy/) | Core reverse proxy built on Pingora |\n| [`sentinel-config`](crates/config/) | KDL configuration parsing and validation |\n| [`sentinel-agent-protocol`](crates/agent-protocol/) | Agent protocol v1 (legacy) and v2 (current) |\n| [`sentinel-common`](crates/common/) | Shared types, errors, and utilities |\n| [`wasm-runtime`](crates/wasm-runtime/) | WASM agent runtime using Wasmtime |\n| [`playground-wasm`](crates/playground-wasm/) | Browser bindings for the config playground |\n| [`sim`](crates/sim/) | WASM-compatible configuration simulator |\n| [`stack`](crates/stack/) | All-in-one process manager for proxy and agents |\n\n\u003c/details\u003e\n\n## Control Plane\n\n[**sentinel-control-plane**](https://github.com/raskell-io/sentinel-control-plane) — Fleet management for Sentinel proxies, built with Elixir/Phoenix. Centralized configuration, rolling deploys, and real-time observability across your Sentinel instances.\n\n## Contributing\n\nSee [`CONTRIBUTING.md`](CONTRIBUTING.md) for guidelines.\n\n**Using Claude Code?** See [`.claude/CLAUDE.md`](.claude/CLAUDE.md) for project context, architecture, and coding rules.\n\n## Community\n\n- 📖 [Documentation](https://sentinel.raskell.io/docs) — Guides, reference, and examples\n- 🎮 [Playground](https://sentinel.raskell.io/playground/) — Try the routing engine in your browser (WASM)\n- 📊 [Benchmarks](https://sentinel.raskell.io/benchmarks/) — Performance, soak testing, and Envoy comparison\n- 💬 [Discussions](https://github.com/raskell-io/sentinel/discussions) — Questions, ideas, show \u0026 tell\n- 🐛 [Issues](https://github.com/raskell-io/sentinel/issues) — Bug reports and feature requests\n\n## License\n\nApache 2.0 — See [LICENSE](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fraskell-io%2Fsentinel","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fraskell-io%2Fsentinel","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fraskell-io%2Fsentinel/lists"}