Repository navigation
prox 1.0.0 is the first public release of a single-binary reverse proxy built for high-throughput HTTP and raw TCP/TLS workloads.
It focuses on readable configuration, safe reloads, and application-specific extensions that run outside the proxy process.
Highlights
- HTTP and TCP on one listener. prox reads the SNI hostname from the TLS ClientHello before termination. Matching connections can be relayed unchanged to raw TCP upstreams, while other domains terminate TLS and continue through HTTP routing.
- Flexible routing and load balancing. Match HTTP traffic by domain, path, method, or headers. Balance L4 and L7 connections using round-robin, random, or least-connections strategies, with health checks and dynamic targets.
- Automatic HTTPS. Issue and renew certificates through Let's Encrypt, ZeroSSL, or custom ACME CAs using TLS-ALPN-01, HTTP-01, or Cloudflare DNS-01. Includes automatic zone discovery, wildcard certificates, OCSP stapling, CA fallback, and S3-compatible certificate storage.
- Readable JSON5 configuration. Split configuration across files, validate it before startup, watch for changes, and apply valid reloads atomically without dropping active connections.
- External plugins and Go SDK. Add authorization, header and response changes, connection gates, speed limits, and dynamic upstream discovery without running extension code inside the proxy process.
- Streaming and persistent connections. Proxy HTTP/1.1, HTTP/2, h2c, WebSocket, streaming, and raw TCP traffic with per-route bandwidth controls.
- Operational API. Inspect health, routes, services, certificates, plugins, and balancers or trigger a configuration reload through the optional authenticated Admin API.
Install
Prebuilt archives are attached for Linux, macOS, and Windows on AMD64 and ARM64. Verify downloaded files with checksums.txt.
Container
docker pull ghcr.io/dortanes/prox:1.0.0
docker run --rm ghcr.io/dortanes/prox:1.0.0 prox versionGo
Go 1.25 or later is required:
go install github.com/dortanes/prox/cmd/prox@v1.0.0
prox versionGet started
Validate a configuration before starting the proxy:
prox validate -config config.json5
prox serve -config config.json5Platform note
Request and response plugin hooks use Unix domain sockets and currently require Linux or macOS. Push-based plugin APIs are also available on Windows.
This is the first public release, so no migration steps are required.
Found a problem or have an idea? Open an issue. If prox is useful in your stack, star the repository so more people can find it.