rathole-org/rathole
63.8
Adequate · 28 September 2026
3.5k
lines of production code
Rust
primary language
2
measurements over time
What this system is
Rathole is a high-performance reverse proxy tool designed for NAT traversal, supporting TCP, UDP, TLS, Noise, and WebSocket transports. It enables secure, low-latency connections between client and server instances with features like hot-reloading configuration and modular transport layers. The system includes benchmarking tools for performance analysis and provides deployment examples for Docker, Nix, and systemd.
Features
Add TLS example with self-signed certificate generation
The examples/tls directory now includes a complete, runnable TLS configuration for both client and server components, along with a shell script to generate the necessary self-signed certificates and keys. Users can now use these files to test encrypted transport by running the provided client and server configurations, which rely on a locally generated root CA and server identity.
examples/tls · high confidence
Add systemd unit file examples for running rathole as a service
The examples/systemd directory now includes systemd unit files (rathole@.service, ratholes@.service, ratholec@.service, etc.) and documentation to help users run rathole as a Linux service. The examples cover both root and non-root execution modes, support running multiple instances via templated units, and include security recommendations such as restricting configuration file permissions.
examples/systemd · high confidence
Added benchmarking scripts for latency and memory usage comparison
New shell scripts and a Gnuplot configuration have been added to the benchmarking suite to facilitate performance comparisons between rathole and frp. The latency benchmark (benches/scripts/http/latency.sh) uses vegeta to measure response times across varying request rates, while the memory usage benchmark (benches/scripts/mem/mem.sh) tracks resident set size (RSZ) for both client and server processes under load. The accompanying plot script (benches/scripts/mem/plot.plt) generates visual graphs of the collected memory data, allowing users to easily assess and compare the resource consumption profiles of the two tools.
benches · high confidence
Initial release of rathole with Docker, Nix, and transport features
This entry marks the initial introduction of the rathole reverse proxy tool, providing a secure, high-performance solution for NAT traversal. The release includes a Dockerfile for containerized deployment and Nix flake support for reproducible builds. Functionally, it supports TCP, TLS, Noise Protocol, and WebSocket transports, with configurable application-layer heartbeats, retry intervals, and TCP\_NODELAY settings to optimize latency and connection stability.
(repo-wide) · high confidence
Introduce modular transport layer with TCP, TLS, Noise, and WebSocket support
The \src/transport\ module now provides a unified, pluggable transport architecture via a \Transport\ trait, allowing connections to be established over plain TCP, TLS (with optional \native-tls\ or \rustls\ backends), Noise protocol encryption, or WebSockets. This change introduces default socket optimizations such as enabling \TCP\_NODELAY\ and configuring TCP keep-alive intervals, while also supporting proxy connections and DNS caching within a single session. Users can now select their preferred transport mechanism and security profile through configuration, with the system handling the underlying handshake and stream wrapping automatically.
src/transport · high confidence
Support for hot-reloading configuration changes and new transport protocols
The application now monitors the configuration file for changes and applies them dynamically without requiring a full restart. Service-level additions or deletions are handled immediately, while general configuration changes trigger a graceful restart. This update also introduces support for multiple transport protocols (TCP, TLS, Noise, and WebSockets) and adds a \--genkey\ CLI command to generate Noise protocol keypairs. Additionally, the protocol version has been bumped to v1, and the application now supports UDP forwarding, configurable retry intervals, and TCP keepalive settings.
src · high confidence
Test coverage
Added common test utilities for TCP and UDP integration testing; Added integration tests for TCP and UDP transports.
Dependencies
Rathole v0.5.0 release with modular features and dependency updates
The application has been updated to version 0.5.0, introducing a modular feature system that allows users to enable or disable capabilities such as server/client modes, TLS (native-tls or rustls), noise protocol, websocket support, and hot-reload. The dependency on the \ring\ crate has been replaced with \sha2\, and other dependencies like \tracing-subscriber\ and \backoff\ have been updated to newer versions. The release profile is now optimized for binary size with LTO and stripping enabled by default.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 56 → 64 (+7.5)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 97 → 97 (+0.0)
- Architecture 100 → 95 (-4.5)
- Maturity 57 → 57 (+0.0)
- Readiness 49 → 67 (+17.5)
- Security 47 → 56 (+9.5)
- Performance 100 (new)
Resolved (2)
- Documentation: no installation or build instructions (README.md)
- Documentation: written for insiders (docs/internals.md)
New (15)
- End-of-life runtime: Rust 1.71
- Outdated: anyhow
- Outdated: async-trait
- Outdated: bytes
- Outdated: futures-core
- Outdated: futures-sink
- Outdated: lazy_static
- Outdated: openssl
- Outdated: rustls-pemfile
- Outdated: serde
- Outdated: tokio
- Outdated: tokio-util
- Outdated: tracing
- Outdated: tracing-subscriber
- Outdated: url
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
rathole-org/rathole was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit a292f7ed5402f840415fc6a53827da2f34337856 — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-d46da229e3fd.