ArchitectureOverview
The proxy
The proxy sends each request to an instance, and it reads only the route table to do it.
The browser sends GET / with the header Host: web.localhost:8080.
1 / 6
The proxy routes by the Host header. On the request path, it never calls the engine or the database. It reads the route table, which gives the upstreams of each hostname.
An upstream is always a port on 127.0.0.1. The networking model tells you why.
If no instance can answer
| Case | Answer of the proxy |
|---|---|
| Unknown host | A 404 page |
| Suspended service | A 503 page |
| No healthy instance | A 503 page with Retry-After |
See Errors of the proxy.
The crates
| Crate | Contents |
|---|---|
ferry-proxy | The RouteTable, the HTTP/1.1 and HTTP/2 reverse proxy with round-robin load balancing, websockets, error pages, TLS termination and connection limits. |
ferry-tls | Automatic HTTPS: ACME HTTP-01 certificates (Let's Encrypt by default), their storage and renewal, and SNI resolution for the proxy. |
The proxy does not depend on ferry-tls. It calls the TlsHooks trait for two things: the answers to ACME challenges, and to know if a host has a certificate. It does the TLS work with the certificate resolver that ferryd gives it. See HTTPS.