Rift logo

Rules are code, not config

The reverse proxy
you can read.

Rift is a programmable single-binary reverse proxy where routing rules are a compiled DSL, not YAML. One static Rust binary on hyper: match host, path, and headers, forward over pooled connections, and stream the response back.

Try the router View on GitHub

write routes, send a request, see which rule wins, first match wins

How to use this playground

Edit the routes.rift box to write routing rules, one per line. Each rule matches on host, path, and headers, then either answers inline (respond) or forwards to an upstream. Order matters: the first rule that matches wins.

Fill in the host, path, and optional header fields to describe an incoming request, and the result panel shows which rule the compiled matcher picks and what it does. Change a rule or the request and the match updates live.

One binary. Compiled rules. Pooled and streaming.

The same matching logic Rift compiles, running here on your rules.

Rules are compiled

The DSL is parsed once into matchers at startup, not re-interpreted from YAML per request. A bad rule fails at check time with the offending line, not in production.

Pooled forwarding

Upstream connections are reused across requests instead of dialed fresh, on top of hyper's HTTP/1.1 and HTTP/2 client.

Streaming

Response bodies stream straight back to the caller, so a large payload never sits buffered in the proxy.

One static binary

No daemon to install, no plugin ecosystem, no reload dance. Point it at a rules file and serve.

Two subcommands. That is the whole surface.

Validate a rules file, then serve it. A bad rule fails at check time with the offending line, never in production.

How it differs

Rift trades a big feature surface for one readable binary. Grounded in what these tools are, not benchmarks.

nginx, Envoy

Config-heavy. Routing lives in large declarative files, and the security-relevant behavior is spread across directives you reload at runtime.

Traefik

Pulls in a lot: dynamic provider integrations, dashboards, and a broad feature surface beyond plain host, path, and header routing.

Rift

One static Rust binary on hyper. Routing is a small rule language compiled once at startup, validated at check time, and forwarded over pooled upstream connections with streaming bodies.

The primitives that matter

Four matchers, two actions.

Every route is matchers plus one action. Matchers all AND together, and the first rule that matches wins.

matcher host

Exact host match, case-insensitive. Reads the Host header on HTTP/1.1 or the URI authority on HTTP/2.

matcher path prefix

Matches when the request path starts with the given string, for example path "/api/".

matcher path ~ regex

Full regex match on the path, for example path ~ "^/v[0-9]+/". Compiled once at startup, and a bad pattern fails at check time.

matcher header

Exact header name and value match, for example header "X-Env" "prod".

action upstream

Forward to a backend URL over a pooled hyper client, streaming the response body straight back to the caller.

action respond

Answer inline with a status code and an optional body, for example respond 200 "ok". No backend needed.

Point it at a rules file and serve.

rift check

Parse and validate a rules file, print the rule count, and exit nonzero naming the offending line if a rule is malformed.

rift serve

Run the HTTP/1.1 and HTTP/2 proxy on --addr with a compiled rules file. Unmatched requests return 502.