Skip to content
CAI
Software that uses CAICheck a score

rathole-org/rathole

63.8

Adequate · 28 September 2026

3.5k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Rathole is a high-performance reverse proxy tool designed for NAT traversal, supporting TCP, UDP, TLS, Noise, and WebSocket transports. It enables secure, low-latency connections between client and server instances with features like hot-reloading configuration and modular transport layers. The system includes benchmarking tools for performance analysis and provides deployment examples for Docker, Nix, and systemd.

Features

Add TLS example with self-signed certificate generation

The examples/tls directory now includes a complete, runnable TLS configuration for both client and server components, along with a shell script to generate the necessary self-signed certificates and keys. Users can now use these files to test encrypted transport by running the provided client and server configurations, which rely on a locally generated root CA and server identity.

examples/tls · high confidence

Add systemd unit file examples for running rathole as a service

The examples/systemd directory now includes systemd unit files (rathole@.service, ratholes@.service, ratholec@.service, etc.) and documentation to help users run rathole as a Linux service. The examples cover both root and non-root execution modes, support running multiple instances via templated units, and include security recommendations such as restricting configuration file permissions.

examples/systemd · high confidence

Added benchmarking scripts for latency and memory usage comparison

New shell scripts and a Gnuplot configuration have been added to the benchmarking suite to facilitate performance comparisons between rathole and frp. The latency benchmark (benches/scripts/http/latency.sh) uses vegeta to measure response times across varying request rates, while the memory usage benchmark (benches/scripts/mem/mem.sh) tracks resident set size (RSZ) for both client and server processes under load. The accompanying plot script (benches/scripts/mem/plot.plt) generates visual graphs of the collected memory data, allowing users to easily assess and compare the resource consumption profiles of the two tools.

benches · high confidence

Initial release of rathole with Docker, Nix, and transport features

This entry marks the initial introduction of the rathole reverse proxy tool, providing a secure, high-performance solution for NAT traversal. The release includes a Dockerfile for containerized deployment and Nix flake support for reproducible builds. Functionally, it supports TCP, TLS, Noise Protocol, and WebSocket transports, with configurable application-layer heartbeats, retry intervals, and TCP\_NODELAY settings to optimize latency and connection stability.

(repo-wide) · high confidence

Introduce modular transport layer with TCP, TLS, Noise, and WebSocket support

The \src/transport\ module now provides a unified, pluggable transport architecture via a \Transport\ trait, allowing connections to be established over plain TCP, TLS (with optional \native-tls\ or \rustls\ backends), Noise protocol encryption, or WebSockets. This change introduces default socket optimizations such as enabling \TCP\_NODELAY\ and configuring TCP keep-alive intervals, while also supporting proxy connections and DNS caching within a single session. Users can now select their preferred transport mechanism and security profile through configuration, with the system handling the underlying handshake and stream wrapping automatically.

src/transport · high confidence

Support for hot-reloading configuration changes and new transport protocols

The application now monitors the configuration file for changes and applies them dynamically without requiring a full restart. Service-level additions or deletions are handled immediately, while general configuration changes trigger a graceful restart. This update also introduces support for multiple transport protocols (TCP, TLS, Noise, and WebSockets) and adds a \--genkey\ CLI command to generate Noise protocol keypairs. Additionally, the protocol version has been bumped to v1, and the application now supports UDP forwarding, configurable retry intervals, and TCP keepalive settings.

src · high confidence

Test coverage

Added common test utilities for TCP and UDP integration testing; Added integration tests for TCP and UDP transports.

Dependencies

Rathole v0.5.0 release with modular features and dependency updates

The application has been updated to version 0.5.0, introducing a modular feature system that allows users to enable or disable capabilities such as server/client modes, TLS (native-tls or rustls), noise protocol, websocket support, and hot-reload. The dependency on the \ring\ crate has been replaced with \sha2\, and other dependencies like \tracing-subscriber\ and \backoff\ have been updated to newer versions. The release profile is now optimized for binary size with LTO and stripping enabled by default.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 56 → 64 (+7.5)
  • Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.

Lenses

  • Code Health 97 → 97 (+0.0)
  • Architecture 100 → 95 (-4.5)
  • Maturity 57 → 57 (+0.0)
  • Readiness 49 → 67 (+17.5)
  • Security 47 → 56 (+9.5)
  • Performance 100 (new)

Resolved (2)

  • Documentation: no installation or build instructions (README.md)
  • Documentation: written for insiders (docs/internals.md)

New (15)

  • End-of-life runtime: Rust 1.71
  • Outdated: anyhow
  • Outdated: async-trait
  • Outdated: bytes
  • Outdated: futures-core
  • Outdated: futures-sink
  • Outdated: lazy_static
  • Outdated: openssl
  • Outdated: rustls-pemfile
  • Outdated: serde
  • Outdated: tokio
  • Outdated: tokio-util
  • Outdated: tracing
  • Outdated: tracing-subscriber
  • Outdated: url

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

rathole-org/rathole was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit a292f7ed5402f840415fc6a53827da2f34337856 — the exact code this score is about.
  • Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-d46da229e3fd.