Rules are code, not config
Rift is a programmable single-binary reverse proxy where routing rules are a compiled DSL, not YAML. One static Rust binary on hyper: match host, path, and headers, forward over pooled connections, and stream the response back.
write routes, send a request, see which rule wins, first match wins
Edit the routes.rift box to write routing rules, one per line. Each rule matches on host, path, and headers, then either answers inline (respond) or forwards to an upstream. Order matters: the first rule that matches wins.
Fill in the host, path, and optional header fields to describe an incoming request, and the result panel shows which rule the compiled matcher picks and what it does. Change a rule or the request and the match updates live.
The same matching logic Rift compiles, running here on your rules.
The DSL is parsed once into matchers at startup, not re-interpreted from YAML per request. A bad rule fails at check time with the offending line, not in production.
Upstream connections are reused across requests instead of dialed fresh, on top of hyper's HTTP/1.1 and HTTP/2 client.
Response bodies stream straight back to the caller, so a large payload never sits buffered in the proxy.
No daemon to install, no plugin ecosystem, no reload dance. Point it at a rules file and serve.
Validate a rules file, then serve it. A bad rule fails at check time with the offending line, never in production.
Rift trades a big feature surface for one readable binary. Grounded in what these tools are, not benchmarks.
Config-heavy. Routing lives in large declarative files, and the security-relevant behavior is spread across directives you reload at runtime.
Pulls in a lot: dynamic provider integrations, dashboards, and a broad feature surface beyond plain host, path, and header routing.
One static Rust binary on hyper. Routing is a small rule language compiled once at startup, validated at check time, and forwarded over pooled upstream connections with streaming bodies.
The primitives that matter
Every route is matchers plus one action. Matchers all AND together, and the first rule that matches wins.
Exact host match, case-insensitive. Reads the Host header on HTTP/1.1 or the URI authority on HTTP/2.
Matches when the request path starts with the given string, for example path "/api/".
Full regex match on the path, for example path ~ "^/v[0-9]+/". Compiled once at startup, and a bad pattern fails at check time.
Exact header name and value match, for example header "X-Env" "prod".
Forward to a backend URL over a pooled hyper client, streaming the response body straight back to the caller.
Answer inline with a status code and an optional body, for example respond 200 "ok". No backend needed.
Parse and validate a rules file, print the rule count, and exit nonzero naming the offending line if a rule is malformed.
Run the HTTP/1.1 and HTTP/2 proxy on --addr with a compiled rules file. Unmatched requests return 502.