WIP: SNI-aware proxy with tokio - #329
selfhoster1312 wants to merge 1 commit into
Conversation
|
Hello @DorianNiemiecSVRJS, i'm still interested in this feature even though this PR is indeed stale! I can rebase on 3.x given some guidance on the new codebase. From what i can read there's now a |
Your PR would implement SNI-aware L4 proxying (if I read it correctly), but Ferron 3's reverse proxy implements L7 proxying, which would require a TLS certificate for the proxy. Yes, you can optionally close this PR and create a new one against the By the way, Ferron 3 uses |
This is really bad code and does everything very wrong, sorry about that, it's just a proof-of-concept. I just submitted this because it took me a while to figure it out already, and people seemed interested in #58 (5 upvotes at the time of writing).
Supports:
It's very quick & dirty, as it will peek in the stream to find the TLS handshake (i couldn't find a peek equivalent in monoio, so only tokio is supported for now), which will be parsed a second time if the connection is not reverse proxied without TLS termination.
Also, i mostly have no idea what i'm doing with that backend
TcpStreamreading/writing, i just hacked this around, but i'm guessing it's possible to pipe actualtcp_streamintodest_streamwithout dark magic (i just don't know how).Testing
It's using the
proxy_tlsdirective in vhosts. For example:Now you can curl it:
Additional notes
rustlswithout consuming the connection (hence the peeked buffer hack), there's plenty of issues about it upstream, and i don't understand why the maintainers don't want to make it easier (i had to fork rustls to make more types public, but there may be a simpler way)