No description
  • Go 98.4%
  • Nix 0.9%
  • Dockerfile 0.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Renovate 07162232f5
All checks were successful
Go check / check-go (push) Successful in 1m28s
Nix check / check-nix (push) Successful in 1m56s
Docker check and push / release (push) Successful in 2m36s
Update module github.com/andybalholm/brotli to v1.2.5 (#68)
This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [github.com/andybalholm/brotli](https://github.com/andybalholm/brotli) | `v1.2.4` → `v1.2.5` | ![age](https://developer.mend.io/api/mc/badges/age/go/github.com%2fandybalholm%2fbrotli/v1.2.5?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/go/github.com%2fandybalholm%2fbrotli/v1.2.4/v1.2.5?slim=true) |

---

### Release Notes

<details>
<summary>andybalholm/brotli (github.com/andybalholm/brotli)</summary>

### [`v1.2.5`](https://github.com/andybalholm/brotli/compare/v1.2.4...v1.2.5)

[Compare Source](https://github.com/andybalholm/brotli/compare/v1.2.4...v1.2.5)

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExNS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->

Reviewed-on: #68
2026-09-25 12:06:36 -07:00
.forgejo/workflows chore(reposyncer): update repo baseline (#67) 2026-09-19 23:45:55 -07:00
cmd/foxIngress Dont add to the default handler 2026-08-06 18:47:55 -07:00
config Add tests 2026-09-18 14:46:31 -07:00
conn Add tests 2026-09-18 14:46:31 -07:00
e2e Add tests 2026-09-18 14:46:31 -07:00
internal/testenv Fix golangci-lint 2026-09-20 00:00:14 -07:00
util Bake in gitrev for nix as well 2026-06-08 22:25:05 -07:00
.dockerignore add dockeringore and add compressed stage 2023-12-01 16:02:30 -08:00
.gitignore boom 2025-10-13 16:54:39 -07:00
config.example.yml Disable on port 0 2026-04-03 20:32:49 -07:00
Dockerfile lint 2026-08-06 10:19:47 -07:00
flake.lock 2605 2026-08-04 13:50:50 -07:00
flake.nix 2605 2026-07-29 22:56:39 -07:00
go.mod Update module github.com/andybalholm/brotli to v1.2.5 (#68) 2026-09-25 12:06:36 -07:00
go.sum Update module github.com/andybalholm/brotli to v1.2.5 (#68) 2026-09-25 12:06:36 -07:00
LICENSE.md Inline go-vhost 2026-07-28 08:36:17 -07:00
README.md Add tests 2026-09-18 14:46:31 -07:00
renovate.json chore(reposyncer): update repo baseline (#50) 2026-07-29 08:14:06 -07:00
vendor-hash.txt Update module github.com/andybalholm/brotli to v1.2.5 (#68) 2026-09-25 12:06:36 -07:00
vendor-hash.txt.doc Update module github.com/prometheus/common to v0.69.0 (#30) 2026-06-18 14:12:58 -07:00

foxIngress

Host-based HTTP(S) router. It can determine the target hostname (and route) connections using the following protocols.

For this, it does not need knowledge of any private keys, even for HTTPS and QUIC (which is the goal of this proxy)

  • HTTP: Host header
  • HTTPS: Client Hello SNI
  • QUIC: Initial Packet SNI

By default it looks for a file called config.yml in the working directory, but this can be influenced with the CONFIG_FILE environment variable.

See config.example.yml for an example config.

Testing

go test ./... -race

The end-to-end suite in e2e starts real listeners on ephemeral loopback ports against a generated config and drives them with real clients, covering all three protocols:

  • HTTP and HTTPS talk to real origin servers. The HTTPS tests complete a genuine TLS handshake at the backend, which is what proves the sniffed ClientHello was replayed byte for byte.
  • QUIC substitutes a trivial line-based host sniffer for the Client Initial Packet parser, via udp.RegisterSniffer. The tests cover foxIngress's own demultiplexing, forwarding and flow lifetime rather than re-testing clienthellod.

The harness lives in internal/testenv. It decodes the PROXY protocol with its own independent implementation, so the header format is genuinely verified rather than round-tripped through the code that wrote it.

MIT licensed