About this project

Sōzu is a lightweight, fast reverse proxy server written in Rust, developed by Clever Cloud. Its defining trait is being "always-up": configuration changes arrive at runtime over secure unix sockets without a reload, and the proxy can upgrade itself while still processing requests. Key capabilities described in the README: - Hot configuration: runtime changes via unix sockets, no restart required. - Zero-downtime upgrades: the master/worker supervisor replaces workers while traffic continues. - TLS termination: acts as a TLS endpoint so backends can stay plain; compile-time choice of cryptographic backends — ring (default), AWS-LC (with post-quantum and FIPS 140-3 options), and OpenSSL. - Network protection: backends are shielded behind the proxy; workers are sandboxed, and Rust provides memory safety. - Performance orientation: zero-copy HTTP handling via the Kawa library and low-overhead TLS via Rustls. - Live operator TUI: `sozu top` (built with the `tui` feature) provides a btop/htop-style dashboard over the command socket, with sparklines, sortable cluster and backend tables, HTTP/2 flood-mitigation counters, and a colour-coded event tail. Installation options include pre-built Linux binaries attached to tagged GitHub releases (covering x86_64 gnu/musl and aarch64 gnu targets across crypto provider variants), Docker images on Docker Hub as `clevercloud/sozu`, and building from source. Releases ship SHA256SUMS, sigstore keyless signatures, and SLSA build-provenance attestations; the README notes that Docker images are built differently from the signed tarballs and are not byte-equivalent. A quickstart requires `protoc` and a pinned Rust toolchain, then `cargo build -p sozu --release --locked` and `target/release/sozu start -c bin/config.toml`. The Cargo workspace contains five crates: `lib` (the reverse proxy library with a single-threaded mio event loop, HTTP/1.1 and HTTP/2 multiplexing, TCP/UDP/TLS protocols, routing, per-IP rate limiting, metrics, buffer pool), `bin` (the supervisor binary, command socket, hot reconfiguration, optional TUI), `command` (protobuf IPC schema, configuration parser, replicated state, FD-passing helpers), `e2e` (integration harness with real workers and mock clients/backends), and `sim` (deterministic simulation of the sans-io UDP core). A separate `fuzz` crate covers frame parsing and HPACK decoding. HTTP/2 support includes flood mitigations for CVE-2023-44487 (Rapid Reset), CVE-2024-27316 (CONTINUATION flood), and CVE-2025-8671 (MadeYouReset), plus PING/SETTINGS/priority floods. Licensing: Sōzu itself is AGPL-3.0-or-later; traffic passing through it is not considered covered work, but a business built on Sōzu's code or algorithms (for example a load-balancer product) is expected to contribute back or arrange a commercial agreement with Clever Cloud. The `sozu-command-lib` crate is LGPL-3.0.