About this project
Sōzu is a lightweight, fast reverse proxy server written in Rust, developed by Clever Cloud. Its defining trait is being "always-up": configuration changes arrive at runtime over secure unix sockets without a reload, and the proxy can upgrade itself while still processing requests.
Key capabilities described in the README:
- Hot configuration: runtime changes via unix sockets, no restart required.
- Zero-downtime upgrades: the master/worker supervisor replaces workers while traffic continues.
- TLS termination: acts as a TLS endpoint so backends can stay plain; compile-time choice of cryptographic backends — ring (default), AWS-LC (with post-quantum and FIPS 140-3 options), and OpenSSL.
- Network protection: backends are shielded behind the proxy; workers are sandboxed, and Rust provides memory safety.
- Performance orientation: zero-copy HTTP handling via the Kawa library and low-overhead TLS via Rustls.
- Live operator TUI: `sozu top` (built with the `tui` feature) provides a btop/htop-style dashboard over the command socket, with sparklines, sortable cluster and backend tables, HTTP/2 flood-mitigation counters, and a colour-coded event tail.
Installation options include pre-built Linux binaries attached to tagged GitHub releases (covering x86_64 gnu/musl and aarch64 gnu targets across crypto provider variants), Docker images on Docker Hub as `clevercloud/sozu`, and building from source. Releases ship SHA256SUMS, sigstore keyless signatures, and SLSA build-provenance attestations; the README notes that Docker images are built differently from the signed tarballs and are not byte-equivalent.
A quickstart requires `protoc` and a pinned Rust toolchain, then `cargo build -p sozu --release --locked` and `target/release/sozu start -c bin/config.toml`.
The Cargo workspace contains five crates: `lib` (the reverse proxy library with a single-threaded mio event loop, HTTP/1.1 and HTTP/2 multiplexing, TCP/UDP/TLS protocols, routing, per-IP rate limiting, metrics, buffer pool), `bin` (the supervisor binary, command socket, hot reconfiguration, optional TUI), `command` (protobuf IPC schema, configuration parser, replicated state, FD-passing helpers), `e2e` (integration harness with real workers and mock clients/backends), and `sim` (deterministic simulation of the sans-io UDP core). A separate `fuzz` crate covers frame parsing and HPACK decoding.
HTTP/2 support includes flood mitigations for CVE-2023-44487 (Rapid Reset), CVE-2024-27316 (CONTINUATION flood), and CVE-2025-8671 (MadeYouReset), plus PING/SETTINGS/priority floods.
Licensing: Sōzu itself is AGPL-3.0-or-later; traffic passing through it is not considered covered work, but a business built on Sōzu's code or algorithms (for example a load-balancer product) is expected to contribute back or arrange a commercial agreement with Clever Cloud. The `sozu-command-lib` crate is LGPL-3.0.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.