About this project
Busbar operates as a customer-operated enforcement boundary for AI systems, rather than a generic reverse proxy. It sits in the request path between AI applications and agents, and downstream destinations including LLM providers, MCP tools, and A2A agents, allowing operators to verify, govern, route, and record model calls, tool use, and agent delegation before requests reach approved destinations. The project is fully self-hosted, with no managed hosted service, no required sign-up, and no outbound phone-home behavior; all provider credentials remain within the operator's own infrastructure at the enforcement boundary. It provides first-class support for six LLM wire protocols on both ingress and egress: OpenAI, OpenAI Responses, Anthropic, Gemini, Cohere, and Bedrock Converse, covering all 36 possible ingress-to-upstream protocol pairs. Same-protocol routes forward original request bytes directly, delivering byte-for-byte parity with direct provider calls, while cross-protocol routes translate request fields to match the target provider's native format. Client integration requires only changing the base URL and API key to point to a Busbar instance, with no changes to existing native SDK workflows. Deployment is designed for minimal operational overhead: Busbar is distributed as a single static Rust binary requiring no separate interpreter, database, or sidecar, or as a small compressed container image. Configuration is defined in a single YAML file, with a built-in config validation command that runs without network access or a running server, suitable for inclusion in CI pipelines. Official Helm charts are provided for Kubernetes deployment, with hardened security defaults including non-root runtime, read-only root filesystem, and dropped unnecessary Linux capabilities. Core operational capabilities include weighted model pools with per-lane concurrency limits, fault-attributed circuit breakers, and in-flight failover that switches providers before the first response byte reaches the client, even for streaming requests. Built-in governance controls include virtual API keys, group-level budgets and spend tracking, native TLS and mTLS support, Prometheus and OTLP telemetry, and per-request audit webhooks. The project's broader execution boundary model extends this same enforcement pattern to MCP tool governance (caller grants, approved schemas, budget enforcement, drift quarantine) and A2A agent trust (verification, pinning, egress control, target-bound credentials). The project publishes benchmark measurements for its own implementation, including p50 added latency of 73 microseconds, 67,837 sustained requests per second with zero failures, 7.3 MiB idle resident memory, and a 5.74 MiB compressed container image, with public comparisons against other common AI gateway and general API gateway tools. The project is released under the Apache 2.0 license, with a SemVer-stable contract for its data-plane HTTP surface and supported wire protocol contracts across major versions.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.