Aralez (Արալեզ), Reverse proxy and service mesh built on top of Cloudflare's Pingora
What Aralez means ?
Aralez = Արալեզ .Named after the legendary Armenian guardian spirit, winged dog-like creature, that descend upon fallen heroes to lick their wounds and resurrect them. .
Built on Rust, on top of Cloudflare’s Pingora engine , Aralez delivers world-class performance, security and scalability — right out of the box.
🔧 Key Features
Dynamic Config Reloads — Upstreams can be updated live via API, no restart required.
TLS Termination — Built-in OpenSSL support.
Automatic load of certificates — Automatically reads and loads certificates from a folder, without a restart.
Upstreams TLS detection — Aralez will automatically detect if upstreams uses secure connection.
Built in rate limiter — Limit requests to server, by setting up upper limit for requests per seconds, per virtualhost.
Global rate limiter — Set rate limit for all virtualhosts.
Per path rate limiter — Set rate limit for specific paths. Path limits will override global limits.
Authentication — Supports Basic Auth, API tokens, and JWT verification.
Basic Auth
API Key via x-api-key header
JWT Auth , with tokens issued by Aralez itself via /jwt API
⬇️ See below for examples and implementation details.
Load Balancing Strategies
Round-robin
Failover with health checks
Sticky sessions via cookies
Unified Port — Serve HTTP and WebSocket traffic over the same connection.
Built in file server — Build in minimalistic file server for serving static files, should be added as upstreams for public access.
Memory Safe — Created purely on Rust.
High Performance — Built with Pingora and tokio for async I/O.
Make sure config folders are correctly mounted. Example configs and full README are in official GitHUB repository https://github.com/sadoyan/aralez
docker run -d \
-v /local/path/to/config:/etc/aralez:ro \
-p 80:80 \
-p 443:443 \
sadoyan/aralez
Copy