Skip to content
CAI
Software that uses CAICheck a score

cloudflare/pingora

62.5

Weak · 27 September 2026

86.1k

lines of production code

Rust

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Pingora is a high-performance, modular Rust framework for building scalable network proxies and load balancers. It provides foundational capabilities for handling HTTP/1.1 and HTTP/2 traffic, including request pipelining, response compression, and caching with configurable eviction policies. The system supports flexible TLS termination and upstream connections through pluggable backends like OpenSSL, BoringSSL, rustls, and s2n-tls, while offering robust service lifecycle management and zero-downtime upgrade features.

How it got here

2023–2024 — Pingora 0.9.0 framework expansion

57 changes.

This period focused on the release of Pingora 0.9.0, introducing a comprehensive modular architecture with new crates for caching, load balancing, and consistent hashing. The work significantly expanded protocol support by adding HTTP/2, gRPC-web bridging, and multiple TLS backends including rustls and s2n-tls. It also enhanced core reliability through sharded connection pooling, graceful upgrade mechanisms, and extensive integration testing.

2025–2026 — s2n-tls integration and telemetry expansion

12 changes.

This period focused on integrating the s2n-tls library for downstream TLS handshake offload and connection handling, alongside introducing alpha subrequest piping utilities. The work also expanded the framework's observability and testing capabilities by adding a dedicated Prometheus metrics crate, a foundations telemetry service, and new HTTP/1.1 pipelining benchmarks.

Features

Add preliminary rustls TLS backend support

Introduces a new TLS implementation using the rustls library alongside the existing OpenSSL/boringssl path. This change adds client and server handshake logic, a rustls-specific TlsRef for accessing peer certificates and cipher details, and support for TLS accept callbacks, enabling users to utilize rustls for TLS connections.

pingora-core/src/protocols/tls/rustls · high confidence

Add s2n-tls connector support with configurable caching

Users can now use the s2n-tls library as a TLS backend for outbound connections by enabling the 's2n' feature. This change introduces a new connector implementation that includes an LRU cache for s2n configurations to improve performance, allowing users to configure the cache size via ConnectorOptions. The implementation supports loading CA certificates and client certificates/keys, and respects peer-specific security policies and connection timeouts.

pingora-core/src/connectors/tls · high confidence

Add s2n-tls integration for TLS connections

This change introduces a new TLS implementation using the s2n-tls library within the pingora-core protocol stack. It adds client and server handshake logic that wraps streams in an auto-flush mechanism to prevent handshake hangs caused by s2n-tls not flushing writes during the connection phase. The implementation includes a custom connection builder to support PSK (Pre-Shared Key) configuration and security policies, and exposes TLS establishment and offload wait time durations via the TimingDigest for observability.

pingora-core/src/protocols/tls/s2n · high confidence

Add s2n-tls support for downstream TLS handshake offload

This change introduces a new TLS listener implementation using the s2n-tls library, allowing users to configure TLS settings such as certificates, security policies, ALPN, and client authentication. A key feature is the ability to offload server-side TLS handshakes to dedicated single-threaded runtime pools, improving performance by separating handshake processing from the main event loop. The implementation includes configuration options for blinding delays, hostname verification, and pre-shared keys (PSK).

pingora-core/src/listeners/tls/s2n · high confidence

Added example service implementations for echo and proxy functionality

This change introduces new example service components in the \pingora/examples/service\ directory, providing ready-to-use patterns for building HTTP echo and proxy services. The \echo.rs\ module exposes factory functions to create \Service\ instances for both standard and HTTP-specific echo applications, while \proxy.rs\ provides similar factories for TCP and TLS-enabled proxy services, including configuration for SNI and certificate paths. These examples demonstrate how to wire up \Pingora\ applications with listening services and upstream peers.

pingora/examples/service · high confidence

Downstream TLS handshake offload and custom ALPN support

The TLS listener implementation now supports offloading server-side TLS handshakes to dedicated single-threaded runtime pools, configurable via \set\_offload\_threadpool\ or automatically from server configuration, which improves performance for high-throughput TLS connections. Additionally, the framework now allows setting custom Application-Layer Protocol Negotiation (ALPN) values via \set\_alpn\, enabling support for protocols beyond the standard HTTP/1.1 and HTTP/2 combinations.

_pingora-core/src/listeners/tls/boringssl\openssl · high confidence

Expanded example suite with new proxy capabilities

The pingora-proxy/examples directory has been significantly expanded with new demonstration code. A new backoff\_retry example shows how to implement retry-able errors with an exponential backoff policy. A connection\_filter example demonstrates the ConnectionFilter trait for early TCP connection filtering. A pipelining example illustrates how to enable HTTP/1.1 request pipelining on the downstream session. A virtual\_l4 example shows how to implement a custom L4 connector with a virtual socket. A grpc\_web\_module example demonstrates bridging gRPC-web client requests to gRPC server requests. A multi\_lb example shows routing to different load balancer clusters based on the request URI. A modify\_response example shows how to modify the response body (converting JSON to YAML). A use\_module example demonstrates how to create and import 3rd party modules. A ctx example shows how to use per-request context. A gateway example shows how to implement a basic gateway with authentication and metrics. A rate\_limiter example shows how to implement rate limiting. A load\_balancer example shows how to implement a basic load balancer with health checks. A conf.yaml configuration file has also been added for the examples.

pingora-proxy/examples · high confidence

Expanded server configuration options for runtime, TLS, and graceful shutdown

The server configuration now exposes a comprehensive set of new options allowing users to tune runtime behavior, TLS debugging, and upgrade processes. Users can now configure graceful shutdown parameters (grace period and timeout), enable upstream TLS key logging for debugging, and adjust Tokio runtime settings such as blocking thread pools, alternative timers, and poll-time histograms. Additionally, the configuration supports parallel listener accepts, configurable upstream retry limits, and signaling mechanisms for zero-downtime upgrades, providing finer control over server stability and performance.

pingora-core/src/server/configuration · high confidence

Extensible TLS handshake data and custom ALPN support

The TLS protocol layer now exposes an extensible \SslDigest\ structure that includes user-defined extensions via a \HandshakeCompleteHook\, allowing applications to attach custom data to the TLS connection state after the handshake. Additionally, the framework supports custom Application-Layer Protocol Negotiation (ALPN) protocols beyond the standard HTTP/1.1 and HTTP/2, enabling negotiation of arbitrary application protocols. This change also introduces preliminary support for the \rustls\ and \s2n-tls\ TLS backends alongside the existing OpenSSL-derived implementation, with feature flags controlling which backend is active.

pingora-core/src/protocols/tls · high confidence

Initial HTTP/2 protocol implementation

Introduces the HTTP/2 client and server session implementations (\pingora-core/src/protocols/http/v2\), enabling the proxy to handle HTTP/2 connections. This includes the handshake logic, request/response header and body handling, configurable read/write timeouts, and validation of authority fields and content-length headers per RFC 9110.

pingora-core/src/protocols/http/v2 · high confidence

Initial release of Pingora LRU library

The pingora-lru crate is introduced as a new component providing an LRU cache implementation optimized for memory efficiency, concurrency, and persistence. It includes a sharded synchronous LRU (\Lru\) with configurable weight limits and item-count watermarks, an asynchronous variant (\AsyncLru\) that separates lock-free reads from actor-based ordering, and a custom memory-efficient doubly linked list. The release also adds shard-level persistence helpers for saving and loading cache state, along with comprehensive benchmarks for the linked list, synchronous LRU, and asynchronous LRU to validate performance characteristics.

pingora-error, pingora-lru · high confidence

Initial release of Pingora core library with modular TLS and connection filtering

This entry introduces the initial version of the Pingora core library, providing the foundational service frameworks and network libraries for building robust, scalable, and secure network infrastructures. The library supports HTTP/1.x and HTTP/2, and features a modular TLS architecture allowing users to choose between OpenSSL (default), BoringSSL (FIPS compatible), Rustls, or s2n-tls via mutually exclusive features. It also introduces an optional early TCP connection filtering capability (via the \connection\_filter\ feature) that allows custom logic to accept or reject connections based on peer address before any TLS handshake or HTTP processing occurs, with zero overhead when disabled. Additionally, the core includes a dedicated offload runtime pool for handling background tasks, such as TLS handshake offloading, with proper task abortion on drop.

pingora-core/src · high confidence

Initial release of Pingora framework

The Pingora crate is introduced as version 0.1.0, providing a framework for building fast, reliable, and programmable networked systems at Internet scale. This initial release exposes core HTTP/1.x and HTTP/2 capabilities, modern TLS support (via OpenSSL or BoringSSL), and zero-downtime upgrade features. The library acts as a facade, re-exporting sub-modules for caching, load balancing, proxying, and time utilities, which are conditionally compiled based on feature flags, while directing users building reverse proxies to the separate pingora-proxy crate.

pingora/src · high confidence

Initial release of pingora-boringssl BoringSSL compatibility layer

This entry introduces the new \pingora-boringssl\ crate, providing a BoringSSL-based API compatibility layer designed to be exchangeable with the existing \pingora-openssl\ implementation. The crate exposes a unified interface for TLS operations, including asynchronous stream handling via \boring\_tokio\ (wrapping \boring::ssl::SslStream\ for \tokio\ integration) and extended SSL configuration utilities in \ext.rs\ (such as certificate loading, host verification, and keying material export). This allows users to switch their underlying TLS provider to BoringSSL without changing their application code.

pingora-boringssl, pingora-openssl · high confidence

Initial release of pingora-cache with LRU eviction and Cache-Control parsing

This entry introduces the pingora-cache library, providing a foundational caching system for the Pingora proxy. It includes a sharded LRU eviction manager (with both synchronous and async variants) to manage cache memory limits, a parser for HTTP Cache-Control headers compliant with RFC 9111, and an admission policy framework to control which cache misses are stored. The release also adds benchmarks for memory usage and serialization performance.

pingora-cache · high confidence

Initial release of pingora-ketama consistent hashing library

This change introduces the pingora-ketama crate, a Rust implementation of the nginx consistent hashing algorithm. It provides a Continuum ring and Bucket nodes with configurable weights to minimize request rehashing during node changes. The release includes a V1 implementation for strict backward compatibility with the previous version and an optional V2 mode (via the v2 feature) that uses a more memory-efficient 6-byte point structure. The crate also ships with benchmarks, a health-aware node selector example, and test data generated from nginx to verify hash consistency.

pingora-ketama · high confidence

Initial release of pingora-s2n TLS integration

This change introduces the pingora-s2n crate, providing a new TLS implementation backed by s2n-tls for use within the Pingora framework. It exposes core s2n-tls components (config, connection, and stream types via tokio) and adds utility functions for loading PEM certificate files and hashing certificates. Additionally, it includes an extension module that implements RFC 5705 keying material export (ssl\_export\_keying\_material) for TLS 1.3 connections and provides a hostname verification callback that bypasses validation.

pingora-s2n · high confidence

Initial release of the pingora-load-balancing crate

The \pingora-load-balancing\ crate is now available, providing core utilities for proxy load balancing. It introduces a \Backend\ model with support for weights and opaque extension fields, and implements selection algorithms including weighted round-robin, random, and Ketama consistent hashing. The crate also includes a \ServiceDiscovery\ interface with a static implementation, configurable TCP and HTTP health checks with callback observability, and a \LoadBalancerGroup\ architecture that shares health state across multiple selectors while managing atomic selector rebuilds and graceful shutdown.

pingora-load-balancing · high confidence

Initial rustls TLS backend support for listeners

This change introduces a new \rustls\-based TLS implementation for the Pingora listener framework, located in \pingora-core/src/listeners/tls/rustls\. It provides a \TlsSettings\ builder and \Acceptor\ struct that allow users to configure TLS endpoints using certificate paths, custom certificate resolvers, ALPN protocols (including HTTP/2), and mutual TLS (mTLS) via client certificate verifiers. The implementation also supports offloading downstream TLS handshakes to dedicated runtime thread pools and integrates with existing TLS accept callbacks. This serves as the foundational backend for rustls-based TLS handling within the framework.

pingora-core/src/listeners/tls/rustls · high confidence

Initial rustls backend integration for TLS operations

This change introduces the \pingora-rustls\ crate, providing a new TLS backend powered by \rustls\ to replace or supplement the previous OpenSSL-based implementation. It exposes core utilities for loading certificates and private keys from PEM files, managing root certificate stores (including native platform certificates), and configuring TLS contexts. The module also integrates \ring\ as the default cryptographic provider and exposes necessary types for server and client TLS streams, enabling users to adopt a modern, pure-Rust TLS stack within the Pingora framework.

pingora-rustls · high confidence

Initial rustls-based TLS connector implementation

The TLS connector in pingora-core has been implemented using the rustls library, replacing or supplementing previous TLS backends. This change introduces support for TLS 1.2 and 1.3, configurable CA certificate stores (including platform defaults and custom files), and optional client certificate authentication (mTLS). It also adds per-peer CA support, allowing specific peers to use distinct certificate authorities, and enables SSLKEYLOGFILE support for debugging encrypted traffic. The implementation handles certificate loading, key management, and TLS handshake configuration via the rustls API.

pingora-core/src/connectors/tls/rustls · high confidence

Introduce HTTP response header serialization with zstd compression

The new \pingora-header-serde\ crate allows HTTP response headers to be serialized into a compressed wire format using zstd, achieving approximately one-third of the original size when a trained dictionary is provided. This feature supports both dictionary-based and default compression modes, with thread-local contexts to optimize performance during serialization and deserialization of cached headers.

pingora-header-serde · high confidence

Introduce Pingora runtime with configurable Tokio options and dial9 telemetry

This release adds the \pingora-runtime\ crate, providing a multi-threaded Tokio runtime variant that avoids work-stealing overhead while supporting multiple cores. Users can now configure blocking pool options (max threads, keep-alive), enable Tokio's experimental alternative timer, and collect poll-time histograms. Additionally, when the \dial9\ feature is enabled, the runtime supports comprehensive telemetry configuration including trace paths, rotation policies, task tracking, and optional S3 uploads for sealed trace segments.

pingora-runtime · high confidence

Introduce TinyUFO cache with S3-FIFO eviction and TinyLFU admission

The \tinyufo/src\ module now provides a new lock-free in-memory cache implementation that uses S3-FIFO for eviction and TinyLFU for admission policy. This change adds the core cache logic, including concurrent storage backends (fast hash map or memory-efficient sharded skip list) and frequency estimation, significantly improving cache hit ratios compared to standard LRU strategies.

tinyufo/src · high confidence

Introduce alpha subrequest piping utility

Added a new \pingora-proxy/src/subrequest\ module providing an alpha-stage utility to pipe data between the main downstream session and a spawned subrequest. This feature allows users to establish a direct pipe, optionally saving or presetting the request body, and exposes the subrequest's outcome (including error states and pipe receiver) via \PipeSubrequestState\. The implementation includes context builders for cache locks and user-defined contexts, and explicitly notes that APIs are unstable.

pingora-proxy/src/subrequest · high confidence

Introduce custom protocol support with client and server session traits

The framework now supports custom HTTP protocols through new \Session\ traits in \pingora-core/src/protocols/http/custom\. This adds a client-side session interface for writing request headers/bodies and reading responses, alongside a server-side session interface for handling incoming requests, writing responses, and managing upgrade states (via \is\_upgrade\_req\ and \was\_upgraded\). The module also provides utilities for custom message streaming (\CustomMessageWrite\, \drain\_custom\_messages\) and a macro for accessing custom sessions, enabling developers to implement and handle non-standard HTTP behaviors.

pingora-core/src/protocols/http/custom · high confidence

Introduce pingora-foundations crate for telemetry integration

Added the new \pingora-foundations\ crate, which provides a \BackgroundService\ to initialize and manage foundations telemetry (logging, metrics, tracing, and a telemetry HTTP server) within Pingora services. This integration allows users to bridge Rust's \log\ crate to foundations' logging pipeline, enable distributed tracing via Jaeger or OpenTelemetry, collect metrics, and expose debugging routes like \/health\ and \/metrics\ through a configurable telemetry server.

pingora-foundations · high confidence

Introduce pingora-http crate for case-preserving HTTP headers and strict request-target parsing

The new pingora-http crate provides HTTP header structures that preserve the original case of header names, enabling transparent proxying without altering traffic. It introduces a dedicated authority classification module that strictly parses request-target boundaries, rejecting ambiguous authorities and forbidden control bytes in HTTP/2 :path headers to prevent normalization mismatches. The crate also includes utilities for case-insensitive header name handling and supports non-UTF-8 request paths.

pingora-http · high confidence

Introduce pingora-memory-cache with read-through support and stale-while-update capabilities

This release introduces the new \pingora-memory-cache\ crate, providing a high-performance in-memory cache built on TinyUFO. It includes a synchronous \MemoryCache\ with support for TTLs, key removal, and a new \get\_stale\ method that returns expired values along with their staleness duration, enabling stale-while-revalidate patterns. Additionally, it provides an asynchronous \RTCache\ (Read-Through Cache) that automatically populates cache entries via a user-provided \Lookup\ callback on misses, featuring lookup coalescing to prevent thundering herd problems.

pingora-memory-cache · high confidence

Introduce pingora-timeout crate with high-performance timeout implementation

The new pingora-timeout crate provides a drop-in replacement for tokio::time::timeout that is optimized for high-concurrency scenarios with frequent timeout creation and cancellation. It features a fast\_timeout mode that uses a dedicated clock thread and shared timer buckets for efficiency, while automatically falling back to Tokio's timeout for long durations (default threshold: 15 minutes) to leverage Tokio's cancellation cleanup. The crate also includes a TimerManager for efficient timer registration and a benchmark suite to validate performance improvements over standard Tokio timeouts.

pingora-timeout · high confidence

Introduce upstream peer abstraction for connection management

The \pingora-core\ library now exposes a new \upstreams\ module containing the \Peer\ trait and \PeerOptions\ struct, providing a standardized interface for defining where and how to connect to remote servers. This change introduces support for configuring TLS settings (including mutual TLS, certificate verification, and SNI), connection timeouts, idle timeouts, and local socket binding, enabling more granular control over upstream connection behavior and reuse.

pingora-core/src/upstreams · high confidence

Introduces early TCP connection filtering via ConnectionFilter trait

Users can now filter incoming connections at the TCP level before TLS handshakes occur by implementing the new \ConnectionFilter\ trait and enabling the \connection\_filter\ feature. This allows applications to drop unwanted connections (e.g., based on IP blocklists) early in the lifecycle, improving security and resource efficiency. The feature is opt-in via a feature flag, with a default \AcceptAllFilter\ ensuring backward compatibility when disabled.

pingora-core/src/listeners · high confidence

New HTTP module system with compression and gRPC-web support

The HTTP module system has been redesigned to support pluggable filters for request and response processing. This change introduces a new \HttpModule\ trait and \HttpModules\ container that allows multiple modules to be registered and executed in a specific order. Two new modules are included: \ResponseCompression\, which handles HTTP response body compression, and \GrpcWebBridge\, which converts HTTP/1.1 gRPC-web requests to H2 gRPC requests. The module system provides hooks for filtering request/response headers, bodies, and trailers, as well as handling response completion.

pingora-core/src/modules/http · high confidence

New HTTP protocol implementation and proxying infrastructure

The HTTP protocol layer in pingora-core has been restructured and expanded with new modules for handling HTTP/1.x and HTTP/2 sessions, including a unified client and server session API. This update introduces strict authority validation for incoming requests to reject ambiguous or malformed targets (such as userinfo in URIs or mismatched Host headers), adds support for gRPC-web bridging to convert between gRPC and gRPC-web protocols, and implements conditional filtering for cache validation using ETag and Last-Modified headers. Additionally, the codebase now includes utilities for body buffering with truncation handling, error response generation, and date caching, providing a more robust foundation for proxying and caching operations.

pingora-core/src/protocols/http · high confidence

New HTTP response compression module with Brotli, Gzip, Zstandard, and dictionary compression

The \pingora-core\ HTTP protocol layer now includes a dedicated compression module that supports compressing outgoing responses using Gzip, Brotli, and Zstandard (zstd), as well as decompressing incoming responses encoded with these algorithms. It also implements RFC 9842 dictionary-compressed Zstandard (dcz) for both compression and decompression, allowing the use of shared dictionaries to improve efficiency for repeated content. The module provides configurable compression levels per algorithm, controls over whether to preserve or weaken ETags when compression is applied, and manages Vary headers to ensure correct caching behavior. This change introduces the core implementation files (\brotli.rs\, \gzip.rs\, \zstd.rs\, and \mod.rs\) that handle the actual encoding/decoding logic, statistics tracking, and header adjustments for HTTP sessions.

pingora-core/src/protocols/http/compression · high confidence

New L4 protocol layer with virtual socket support and cross-platform compatibility

This change introduces a new \pingora-core/src/protocols/l4\ module that provides a unified transport layer implementation. It adds a \Listener\ abstraction supporting both TCP and Unix domain sockets (on Unix), and a \Stream\ type that wraps \TcpStream\, \UnixStream\, and a new \VirtualSocketStream\ for testing or custom socket abstractions. The module exposes detailed TCP connection state via a public \TCP\_INFO\ struct and \SocketDigest\ for retrieving socket options like buffer sizes, keepalive settings, and original destination addresses. It also includes platform-specific support for Windows (via \RawSocket\ and \AsRawSocket\ implementations) and Linux-specific features like TCP fast open, DSCP, and receive timestamp reading, ensuring the L4 layer is functional across different operating systems.

pingora-core/src/protocols/l4 · high confidence

New connection diagnostics and Windows support in protocol layer

The \pingora-core/src/protocols\ module now exposes detailed connection diagnostics via a new \Digest\ system, allowing users to inspect TLS state, socket details, and timing metrics (such as establishment duration and offload wait times) for each connection layer. Socket information is accessible through \SocketDigest\, which provides methods to retrieve peer/local addresses, TCP info, receive/send buffer sizes, and the Linux socket cookie. Additionally, the module introduces \ProxyDigest\ to capture CONNECT proxy response headers and arbitrary user data, and adds platform-specific implementations to support Windows, including raw socket handling and address resolution.

pingora-core/src/protocols · high confidence

New example applications for TCP, HTTP, and proxying

The pingora examples directory now includes a comprehensive set of demonstration applications. These include a basic TCP echo server, an HTTP echo server with request body handling and timeouts, a TCP proxy that duplexes streams to an upstream peer, an HTTP client example demonstrating session management and response parsing, and a graceful upgrade example showcasing background service dependencies and daemon readiness signaling. Additionally, the main server example demonstrates configuration of TCP fast open, TCP keepalive settings, and TLS with dynamic certificate callbacks.

pingora/examples · high confidence

New examples for service dependency management and client certificate TLS inspection

Added three new examples in pingora-core/examples to demonstrate advanced server configuration patterns. The service\_dependencies.rs example illustrates how to declare and manage service-level dependencies using ServiceHandle, ensuring services start in the correct order and wait for dependencies to be ready. The bootstrap\_as\_a\_service.rs example shows how to integrate the server bootstrap phase into the service dependency graph, allowing other services to depend on bootstrap completion without blocking the main thread. The client\_cert.rs example demonstrates how to inspect TLS handshake details, including SNI, Subject Alternative Names (SANs), and Common Names (CN) from client certificates, using the handshake\_complete\_callback. Supporting test keys and certificates for the client\_cert example have also been added.

pingora-core/examples · high confidence

New file descriptor transfer module for graceful upgrades

Added a new \transfer\_fd\ module in \pingora-core\ that enables the serialization and transfer of listening file descriptors between processes via Unix sockets, supporting graceful upgrades. The module includes logic to close unclaimed inherited listening sockets to prevent connection black-holing and handles socket permissions and retry logic for reliable descriptor passing.

_pingora-core/src/server/transfer\fd · high confidence

New owned HTTP/1 test origin for integration testing

The \pingora-test-utils\ crate now includes an \HttpOrigin\ component that allows integration tests to spin up a local, ephemeral HTTP/1 server. This utility binds to a random localhost port by default, accepts a custom request handler, and provides methods to retrieve the listening address and URL. It supports explicit shutdown to wait for cleanup and surface handler panics, or automatic cleanup via \Drop\, enabling tests to verify request handling, connection lifecycle, and error propagation without external dependencies.

pingora-test-utils · high confidence

New pingora-prometheus crate for serving metrics

A new \pingora-prometheus\ crate has been introduced to provide a dedicated Prometheus metrics HTTP server for Pingora services. This component exposes collected static metrics via an HTTP endpoint, offering both a basic \PrometheusHttpApp\ and a \PrometheusServer\ variant with gzip compression enabled. Users can easily integrate this by adding the provided \prometheus\_http\_service()\ to their server configuration, ensuring metrics are served on a dedicated listener to avoid conflicts with other routes.

pingora-prometheus · high confidence

New service dependency system and refined daemonization with graceful upgrade support

The server module now includes a new \bootstrap\_services.rs\ file that introduces a \BootstrapService\ and a dependency graph system, allowing server bootstrapping to be delayed until dependent services are ready. Daemonization logic has been moved to \daemon.rs\ and switched from the \daemonize\ crate to \daemonix\, adding support for dropping privileges in the parent process and signaling readiness via \SIGUSR1\. The \mod.rs\ file exposes a comprehensive \ExecutionPhase\ enum to track server lifecycle states (from Setup to Terminated) and defines \ShutdownSignal\ types for graceful upgrades, graceful termination, and fast shutdown, enabling more precise control over shutdown behavior and graceful upgrade handoffs.

pingora-core/src/server · high confidence

New service lifecycle and dependency management system

The service architecture has been refactored to support explicit service dependencies and a background service model. Listening services can now declare dependencies on other services, ensuring they only start after their dependencies have signaled readiness via the new ServiceReadyNotifier. A new BackgroundService trait allows for non-request-handling logic (like service discovery) to run alongside the main server lifecycle. Additionally, proxy services can now override global runtime options to customize their execution environment.

pingora-core/src/services · high confidence

Rate estimator now supports custom rate calculation functions

The \pingora-limits\ rate estimator now allows users to define custom rate calculation logic via the new \rate\_with\ method and \RateComponents\ struct. This enables flexible rate estimation strategies, such as linear interpolation between current and previous interval counts, rather than relying solely on the default average rate of the last completed period. The module also includes a new \new\_with\_estimator\_config\ constructor to customize the underlying hash/slot configuration and refactors internal \Estimator\ logic to use iterator-based initialization and folding for cleaner code.

pingora-limits · high confidence

Support for custom upstream protocols via pluggable connectors

The HTTP connector now supports connecting to upstreams using custom protocols beyond standard HTTP/1.1 and HTTP/2. A new \custom\ module introduces a \Connector\ trait and a \Connection\ enum, allowing users to implement and register their own session handling logic. The main \Connector\ struct has been refactored to manage H1, H2, and custom sessions, with logic in \get\_http\_session\ to detect and route traffic to custom connectors based on ALPN settings. This enables extensibility for non-standard protocols while maintaining existing HTTP behavior.

pingora-core/src/connectors/http · high confidence

TLS backend abstraction supports rustls and s2n-tl alongside OpenSSL

The TLS utility module in pingora-core now provides a unified certificate inspection API (organization, serial, common name, and expiration) that works across three TLS backends: the existing OpenSSL/BoringSSL implementation, a new rustls implementation, and a new s2n-tls implementation. Users can now select their preferred TLS backend via feature flags (openssl\_derived, rustls, s2n), and the library will expose consistent certificate metadata extraction regardless of the underlying crypto provider, enabling easier switching between backends without changing application code that relies on certificate details.

pingora-core/src/utils/tls · high confidence

TLS backend selection via feature flags

The TLS listener module now supports selecting the underlying TLS implementation through Cargo features. Users can choose between BoringSSL/OpenSSL (via the \openssl\_derived\ feature), rustls (via the \rustls\ feature), or s2n-tls (via the \s2n\ feature), with the module conditionally exporting the corresponding implementation based on the enabled feature.

pingora-core/src/listeners/tls · high confidence

Architecture

Refactor TLS implementation into modular subcomponents

The \boringssl\_openssl\ TLS module has been restructured into distinct submodules (\client\, \server\, \stream\) to improve code organization and prepare for future integration with rustls. This change introduces a dedicated \SslStream\ wrapper that manages TLS state, timing metrics, and digest information, while separating client-side handshake logic (including extension handling) from server-side logic (including resumable accept and certificate callbacks). The refactoring maintains existing functionality for both BoringSSL and OpenSSL backends but organizes the codebase for better maintainability.

_pingora-core/src/protocols/tls/boringssl\openssl · high confidence

Behavioural changes

HTTP server now supports request pipelining and user-extensible connection context

The HTTP application layer in pingora-core now supports HTTP/1.1 request pipelining on downstream sessions, allowing multiple requests to be sent over a single keepalive connection without waiting for previous responses. Additionally, the \HttpPersistentSettings\ struct has been extended to carry a user-defined context across keepalive reuses, enabling applications to persist state (such as authentication tokens or session data) between requests on the same connection. The \HttpServer\ struct also now integrates with an \HttpModules\ system, allowing middleware to filter request and response headers and bodies during processing.

pingora-core/src/apps · high confidence

Introduce sharded global LRU connection pool with eviction pressure benchmarks

The \pingora-pool\ crate now implements a connection pooling strategy that replaces the previous thread-local LRU with a sharded global LRU cache, ensuring that idle connections are evicted based on true global usage rather than per-thread history. This change improves resource management by preventing stale entries from persisting in the pool and includes new microbenchmarks to validate performance under eviction pressure and high concurrency.

pingora-pool · high confidence

New HTTP/1.x protocol implementation

The HTTP/1.x protocol handling has been replaced with a new implementation located in pingora-core/src/protocols/http/v1. This new module introduces dedicated body parsing and writing state machines (body.rs), a cancel-safe header writer for proxy task APIs (header.rs), and updated client and server session structures (client.rs, server.rs). The changes bring support for HTTP/1.1 request pipelining, robust chunked transfer-encoding parsing, and configurable keep-alive and timeout behaviors, fundamentally changing how HTTP/1 traffic is processed compared to the previous version.

pingora-core/src/protocols/http/v1 · high confidence

New cancel-safe subrequest session API with robust body handling

The subrequest module now provides a new HTTP server session implementation that supports a cancel-safe proxy task API, allowing tasks to be queued and committed safely. This change introduces dedicated body reader and writer components that handle HTTP body parsing with improved robustness, including specific fixes for upgrade handling when the body is not initialized, avoidance of close-delimited mode on HTTP/1.0 requests, and stricter rejection of invalid Content-Length values. The session also clears request body headers when no input is provided and correctly transitions to upgrade body mode upon receiving a 101 response, ensuring reliable proxying behavior for subrequests.

pingora-core/src/protocols/http/subrequest · high confidence

Pingora 0.9.0 release with sharded connection pooling and upstream module system

This release introduces a reworked connection pooling mechanism using sharded storage and a true global LRU to eliminate stale entries and race conditions, alongside a new upstream module system that allows processing before upstream compression. It also adds an upstream module system for pre-compression processing, splits Prometheus integration into a separate optional crate, and enforces bounded default HTTP/2 server limits to mitigate memory exhaustion. The minimum supported Rust version (MSRV) is raised to 1.85 for most crates and 1.88 for pingora-foundations, and RequestHeader/ResponseHeader no longer implement DerefMut to prevent internal invariant violations.

(repo-wide) · high confidence

Sharded shutdown notification to reduce lock contention

The proxy now uses a sharded \Notify\ mechanism for shutdown signals, distributing waiters across multiple shards based on worker threads to avoid a single lock becoming a contention bottleneck on multi-core systems. This change improves shutdown performance under high concurrency by ensuring that waiter registration and notification operations are spread across independent synchronization primitives rather than contending on a single global lock.

pingora-proxy/src · high confidence

Upstream TLS connector now supports dynamic ECDH curves and client certificate chains

The TLS connector implementation for upstream connections has been updated to allow more flexible configuration. Users can now specify ECDH curves dynamically via peer options, enabling runtime determination of key exchange parameters. Additionally, the connector properly handles mutual TLS (mTLS) by loading client certificate chains, including intermediate certificates, directly from peer configurations rather than relying solely on static file paths. This change also refactors the underlying OpenSSL/BoringSSL initialization to use standard environment variable probing for CA certificates.

_pingora-core/src/connectors/tls/boringssl\openssl · high confidence

Upstream connection management refactored with global LRU pool and configurable socket options

The upstream connector module has been restructured to improve reliability and configurability. The connection pool now uses a true global Least Recently Used (LRU) strategy instead of thread-local caches, preventing stale entries and improving connection reuse across workers. The L4 connection layer now exposes granular socket configuration options, allowing users to set TCP receive buffer sizes, DSCP values, and TCP Fast Open settings. Additionally, the connector supports binding to specific local IP addresses and port ranges (with fallback on Linux 6.3+), and offers an optional offload threadpool to isolate CPU-intensive TCP/TLS establishment from the main event loop. Debugging capabilities are enhanced with SSLKEYLOG support for traffic decryption and callbacks to track idle connection ages.

pingora-core/src/connectors · high confidence

Test coverage

Add TinyUFO cache benchmark suite; Add mock origin server configuration for tests; Added HTTP/1.1 pipelining benchmarks; Added integration tests for server lifecycle, shutdown behavior, and TLS connectivity; Added test certificates and keys for TLS backends; Added test certificates for s2n-tls support; Added test fixtures for EC key pair and self-signed certificate; Added test keys symlink for server example; Added test utilities for HTTP and H2C echo server scenarios; Added test utilities for TLS certificate handling and mock origin setup; Initial integration test suite for Pingora proxy.

Dependencies

Pingora 0.9.0 release with new TLS providers and workspace restructuring

This release updates the Pingora framework to version 0.9.0, introducing new optional TLS providers via the \pingora-boringssl\ and \pingora-s2n\ crates, and adding a new \pingora-foundations\ crate for telemetry integration. The workspace has been restructured to include several new sub-crates such as \pingora-ketama\, \pingora-load-balancing\, \pingora-memory-cache\, and \pingora-prometheus\. Key dependency updates include bumping \openssl\ to 0.10.72 to address security vulnerabilities, upgrading \h2\ to \>=0.4.16, and updating \lru\ to 0.18.2. The release also enforces stricter MSRV requirements (e.g., Rust 1.85 for \pingora-cache\ and 1.88 for \pingora-foundations\) and refactors feature flags to better support modular TLS and proxy functionality.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 42 → 62 (+20.7)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 100 → 83 (-16.5)
  • Architecture 88 (new)
  • Maturity 61 → 67 (+6.3)
  • Readiness 19 → 50 (+30.9)
  • Security 55 → 77 (+21.2)

Resolved (16)

  • Dimension evaluation failed
  • High IaC: DS-0002 (Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • Low IaC: DS-0026 (Dockerfile)
  • No automated tests
  • No exposed public API
  • No tests found
  • Test reliability not included
  • The Pingora User Manual section links only to internal docs (quick_start.md and user_guide/index.md) but the API Reference is present in the body, so a dedicated reference doc would make this section self-contained. (docs/README.md)

New (566)

  • BodyReader::do_read_chunked_body (cognitive 50) (pingora-core/src/protocols/http/v1/body.rs)
  • BodyReader::do_read_chunked_body_final (cognitive 31) (pingora-core/src/protocols/http/v1/body.rs)
  • BodyReader::parse_chunked_buf (cognitive 41) (pingora-core/src/protocols/http/v1/body.rs)
  • BodyReader::validate_crlf (cognitive 21) (pingora-core/src/protocols/http/v1/body.rs)
  • BodyWriter::poll_write_content_length_body_task (cognitive 21) (pingora-core/src/protocols/http/v1/body.rs)
  • CachePutCtx::do_cache_put (cognitive 24) (pingora-cache/src/put.rs)
  • ClassTooLong: BodyReader (pingora-core/src/protocols/http/v1/body.rs)
  • ClassTooLong: BodyWriter (pingora-core/src/protocols/http/v1/body.rs)
  • ClassTooLong: HttpCache (pingora-cache/src/lib.rs)
  • ClassTooLong: HttpProxy (pingora-proxy/src/lib.rs)
  • ClassTooLong: HttpSession (pingora-core/src/protocols/http/subrequest/server.rs)
  • ClassTooLong: HttpSession (pingora-core/src/protocols/http/v1/client.rs)
  • ClassTooLong: HttpSession (pingora-core/src/protocols/http/v1/server.rs)
  • ClassTooLong: Session (pingora-core/src/protocols/http/server.rs)
  • Connector::get_http_session (cognitive 17) (pingora-core/src/connectors/http/mod.rs)
  • CustomMessageForwarder::proxy (cognitive 23) (pingora-proxy/src/proxy_custom.rs)
  • Dependency hygiene PARTLY measured — Cargo dependencies read, no committed lock to grade for currency
  • Documentation: no installation or build instructions (docs/user_guide/index.md)
  • Documentation: no usage examples (docs/user_guide/index.md)
  • Duplicate method signature with different parameter names. This suggests a copy-paste error or an accidental overload that does not add value.
  • …and 546 more

Changes since last survey

  • 69 commits — 63 feature/other, 6 fixes

By area

  • (root) — 29 commits
  • pingora-core/src — 14 commits
  • pingora-cache/src — 9 commits
  • pingora-proxy/src — 5 commits
  • pingora-load-balancing/src — 4 commits
  • .github/workflows — 3 commits
  • pingora-proxy/tests — 2 commits
  • .cargo/audit.toml — 1 commit
  • docs/user_guide — 1 commit
  • pingora-http/src — 1 commit

Notable commits

  • fix: Fix downstream HTTP/2 idle timeout tracking
  • fix: Fix load balancer shutdown responsiveness
  • fix: Fix racy closes_only_unclaimed_fds tests
  • fix: Fix shutdown sleeping twice for graceful timeout
  • fix: Fix stale CacheKey test constructors
  • fix: Revert "Acknowledge downstream h2 RST_STREAM while the upstream request-body write is blocked."
  • change: Abort tls offload tasks when dropped
  • change: Acknowledge downstream h2 RST_STREAM while the upstream request-body write is blocked.
  • change: Add 'is_header_phase' function to compression module
  • change: Add Acceptor::from_server_config for runtime-built rustls ServerConfig
  • change: Add RST_STREAM cancellation test on idle streams
  • change: Add an optional idle timeout for downstream HTTP/2 connections
  • change: Add pingora-foundations crate
  • change: Add snapshot readiness for selectors
  • change: Add tests for graceful shutdown
  • change: Address borrowed purge review feedback
  • change: Address foundations review feedback
  • change: Avoid cloning cache keys during purge
  • change: Avoid copying buffered HTTP/1 pipelines
  • change: Build OpenResty from source in GitHub CI
  • …and 49 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

cloudflare/pingora was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4487f7b2ab50f159e4a2cf4f6a6b813f61bb6e19 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.