- Go 98.4%
- Nix 0.9%
- Dockerfile 0.7%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [github.com/andybalholm/brotli](https://github.com/andybalholm/brotli) | `v1.2.4` → `v1.2.5` |  |  | --- ### Release Notes <details> <summary>andybalholm/brotli (github.com/andybalholm/brotli)</summary> ### [`v1.2.5`](https://github.com/andybalholm/brotli/compare/v1.2.4...v1.2.5) [Compare Source](https://github.com/andybalholm/brotli/compare/v1.2.4...v1.2.5) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExNS40IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119--> Reviewed-on: #68 |
||
| .forgejo/workflows | ||
| cmd/foxIngress | ||
| config | ||
| conn | ||
| e2e | ||
| internal/testenv | ||
| util | ||
| .dockerignore | ||
| .gitignore | ||
| config.example.yml | ||
| Dockerfile | ||
| flake.lock | ||
| flake.nix | ||
| go.mod | ||
| go.sum | ||
| LICENSE.md | ||
| README.md | ||
| renovate.json | ||
| vendor-hash.txt | ||
| vendor-hash.txt.doc | ||
foxIngress
Host-based HTTP(S) router. It can determine the target hostname (and route) connections using the following protocols.
For this, it does not need knowledge of any private keys, even for HTTPS and QUIC (which is the goal of this proxy)
- HTTP: Host header
- HTTPS: Client Hello SNI
- QUIC: Initial Packet SNI
By default it looks for a file called config.yml in the working directory, but this can be influenced with the CONFIG_FILE environment variable.
See config.example.yml for an example config.
Testing
go test ./... -race
The end-to-end suite in e2e starts real listeners on ephemeral loopback ports against a generated config and drives them with real clients, covering all three protocols:
- HTTP and HTTPS talk to real origin servers. The HTTPS tests complete a genuine TLS handshake at the backend, which is what proves the sniffed ClientHello was replayed byte for byte.
- QUIC substitutes a trivial line-based host sniffer for the Client Initial
Packet parser, via
udp.RegisterSniffer. The tests cover foxIngress's own demultiplexing, forwarding and flow lifetime rather than re-testingclienthellod.
The harness lives in internal/testenv. It decodes the PROXY protocol with its own independent implementation, so the header format is genuinely verified rather than round-tripped through the code that wrote it.
MIT licensed