A lightweight HTTPS reverse proxy written in Rust
846
A lightweight, high-performance HTTPS reverse proxy written in Rust. Designed for local development with Docker Compose to easily route traffic to multiple backend services with automatic self-signed TLS certificates.
wss:// -> ws://).Create a routes.yaml file to define your routing rules:
listeners:
- port: 440
target: http://api:3000 # Local API service
- port: 441
target: http://app:3001 # Local Web App
- port: 442
target: https://httpbin.org # External HTTPS service
- port: 443
target: http://ws-echo:8080 # WebSocket service
docker-compose.ymlAdd the proxy service to your composition:
services:
proxy:
image: manhpv151090/https:latest
platform: linux/amd64
ports:
- "440:440"
- "441:441"
- "442:442"
- "443:443"
volumes:
- ./routes.yaml:/etc/proxy/routes.yaml:ro
- ./certs:/certs
docker compose up --build
curl -k https://localhost:440/
wscat -n -c wss://localhost:443/ws
The routes.yaml file supports the following structure:
listeners:
- port: <LISTENING_PORT>
target: <UPSTREAM_URL>
http://, https://, and ws://.| Variable | Default | Description |
|---|---|---|
RUST_LOG | https_proxy=info | Logging level (supported: error, warn, info, debug, trace). |
.
āāā proxy/ # HTTPS reverse proxy crate
ā āāā src/
ā ā āāā main.rs # Entry point, server setup
ā ā āāā lib.rs # Library exports
ā ā āāā config.rs # YAML config loading
ā ā āāā proxy.rs # Core proxy logic, WebSocket handling
ā ā āāā tls.rs # TLS configuration
ā āāā tests/
ā ā āāā integration_test.rs
ā āāā Cargo.toml
āāā manage-ca/ # CA certificate management CLI
ā āāā src/
ā ā āāā main.rs # CLI entry point + NSS/browser cert management
ā āāā Cargo.toml
āāā Cargo.toml # Workspace manifest
āāā Dockerfile # Multi-stage Docker build
āāā entrypoint.sh # Docker entrypoint (CA + cert generation)
āāā docker-compose.yml # Example composition with demo services
āāā routes.yaml # Example routes config
āāā LICENSE
If you have Rust installed, you can run the project natively:
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
cargo run --release
To build the Docker image locally:
docker build -t my-https-proxy .
cargo test --all-features
By default, the container automatically generates a Certificate Authority (CA) and server certificates on startup. The CA certificate is stored in the certs/ca/ directory.
Important: Make sure to mount the certs directory in your docker-compose.yml:
volumes:
- ./routes.yaml:/etc/proxy/routes.yaml:ro
- ./certs:/certs
To avoid browser security warnings, use the manage-ca CLI tool to install the CA certificate.
Prerequisites:
| OS | Required Software |
|---|---|
| Linux | libnss3-tools (for Chrome/Chromium NSS DB) |
| macOS | None (uses built-in security command) |
| Windows | None (uses built-in certutil.exe) |
# Ubuntu/Debian
sudo apt install libnss3-tools
# Fedora/RHEL
sudo dnf install nss-tools
# Arch
sudo pacman -S nss
Option 1: Download from GitHub Releases
Linux:
curl -L -o manage-ca https://github.com/manhpham90vn/https/releases/latest/download/manage-ca-linux-amd64
chmod +x manage-ca
sudo ./manage-ca install
macOS:
# Intel
curl -L -o manage-ca https://github.com/manhpham90vn/https/releases/latest/download/manage-ca-macos-amd64
# Apple Silicon
curl -L -o manage-ca https://github.com/manhpham90vn/https/releases/latest/download/manage-ca-macos-arm64
chmod +x manage-ca
sudo ./manage-ca install
Windows (PowerShell as Administrator):
Invoke-WebRequest -Uri "https://github.com/manhpham90vn/https/releases/latest/download/manage-ca-windows-amd64.exe" -OutFile manage-ca.exe
.\manage-ca.exe install
Option 2: Build from source
cargo build --release -p manage-ca
sudo ./target/release/manage-ca install # Linux/macOS
.\target\release\manage-ca.exe install # Windows (as Admin)
Custom cert path:
sudo ./manage-ca install --cert /path/to/ca.crt
After installation, restart your browsers.
sudo ./manage-ca uninstall # Linux/macOS
.\manage-ca.exe uninstall # Windows (as Admin)
If you prefer not to use manage-ca, you can import the certificate manually.
Linux (Ubuntu/Debian):
sudo cp certs/ca/ca.crt /usr/local/share/ca-certificates/local-dev-ca.crt
sudo update-ca-certificates
Linux (Fedora/RHEL/Arch):
sudo cp certs/ca/ca.crt /etc/pki/ca-trust/source/anchors/local-dev-ca.crt
sudo update-ca-trust extract
Chrome/Chromium/Edge:
chrome://certificate-managercerts/ca/ca.crtFirefox:
about:preferences#privacycerts/ca/ca.crtmacOS (manual):
sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain certs/ca/ca.crt
Windows (manual):
certutil -addstore Root certs\ca\ca.crt
Port Conflicts:
If a port is already in use on your host, change the mapping in docker-compose.yml (e.g., "8443:443" maps host port 8443 to container port 443).
Certificate Errors:
Since self-signed certificates are used by default, browsers and tools like curl will warn about security.
-k or --insecure flag.This project is open source and available under the MIT Licenseā .
Content type
Image
Digest
sha256:b84dd9245ā¦
Size
6.7 MB
Last updated
7 months ago
docker pull manhpv151090/https