About this project
Rama is a modular service framework for the Rust language, designed for building network clients, servers, proxies, and combinations thereof. It emphasizes an explicit, composable architecture where the network stack is built from services, layers, transports, protocols, and state that you compose yourself, making the system's shape visible in code.
Key capabilities include:
- **Proxies**: Reverse, TLS termination, HTTP(S), SOCKS5, SNI, MITM, transparent, distortion, and network proxies, plus HAProxy PROXY protocol support.
- **Web applications and APIs**: Path and matcher routing, async handlers with typed request extractors and shared state, typed HTML/JSON/streaming responses, forms and file uploads, static assets, and middleware for authentication, CSRF, CORS, compression, timeouts, and tracing.
- **Clients and connector stacks**: Async HTTP(S) clients for HTTP/1.1, HTTP/2, HTTP/3 with Alt-Svc discovery, WebSocket, gRPC, ttRPC, FastCGI clients, custom connector stacks, connection pools, and User-Agent emulation with real-browser profiles.
- **Servers and ingress controls**: HTTP/1.1, HTTP/2, HTTP/3 servers, WebSocket, SSE, gRPC, ttRPC, TCP/UDP/QUIC/Unix transports, TLS termination with dynamic certificates, mTLS, ACME, protocol inspection, and fingerprinting (JA3, JA4, PeetPrint, JA4H, Akamai HTTP/2).
- **Application protocols and gateways**: WebSockets, SSE, Datastar, gRPC, ttRPC, FastCGI, RSS/Atom feeds.
- **Proxy routing and discovery**: Explicit routes, upstream proxies, PAC fetching/evaluation/generation, bypass rules, route failure caching.
- **Content adaptation**: ICAP clients/servers and HTTP adaptation layers.
- **Runtime and interoperability**: Async services, optional blocking adapters, Tower interoperability, graceful shutdown.
- **TLS and identity**: Rustls, BoringSSL, TLS termination, dynamic certificates, mTLS, ACME, certificate pinning.
- **Traffic inspection**: Protocol inspection, HTTP/WebSocket/TLS capture and interception, MITM proxy with web UI, HAR recording/replay, curl export.
- **Data processing**: Streaming HTML rewriting, streaming JSON/JSONPath selection and rewriting, JSON-LD.
- **Observability**: Tracing and OpenTelemetry, HTTP and transport metrics, runtime telemetry.
- **Embedded scripting**: JavaScript runtime for PAC evaluation and generation.
- **Lower-level networking**: TCP, UDP, QUIC v1/v2, Unix sockets, DNS, transport middleware, connection pooling.
- **Platform integrations**: Apple Network Extension, Apple XPC, Linux tproxy, Windows WFP.
The `rama` CLI binary allows using parts of Rama without writing Rust code, including running HTTP(S)/SOCKS5 proxies with MITM mode and web UI, HTTP/WebSocket clients, DNS resolution, TLS probing, PAC evaluation, and test services.
The framework is developed by Plabayo and is used in production for network security, data extraction, API gateways, and routing. It requires Rust 1.96 and supports Linux, macOS, and Windows as tier 1 platforms.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.