Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
40 changes: 40 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,46 @@ jobs:
if: matrix.backend.name == 'rust_crypto'
run: cargo publish --dry-run --features cli

# The release packages ship static musl binaries; build and test that target
# on every change, so a dependency that breaks it fails here, not at release.
musl:
name: musl (${{ matrix.target }})
runs-on: ${{ matrix.runs-on }}
strategy:
fail-fast: false
matrix:
include:
- target: x86_64-unknown-linux-musl
runs-on: ubuntu-latest
- target: aarch64-unknown-linux-musl
runs-on: ubuntu-24.04-arm
steps:
- uses: actions/checkout@v7
with:
persist-credentials: false
- uses: dtolnay/rust-toolchain@stable
with:
targets: ${{ matrix.target }}
- name: Install musl tools
run: |
sudo apt-get update
sudo apt-get install -y musl-tools
# Third-party action: pinned to a commit SHA (dependabot keeps it fresh).
- uses: Swatinem/rust-cache@e18b497796c12c097a38f9edb9d0641fb99eee32 # v2
with:
key: ${{ matrix.target }}
# Third-party action: pinned to a commit SHA (dependabot keeps it fresh).
- uses: taiki-e/install-action@94c31af3204a9f15ab40b35ad084410b905bbc73 # v2
with:
tool: cargo-nextest

# The build the release workflow packages.
- name: Build
run: cargo build --release --target ${{ matrix.target }} --features cli --bin structured-proxy

- name: Test
run: cargo nextest run --target ${{ matrix.target }} --features cli

security-audit:
name: Security Audit
runs-on: ubuntu-latest
Expand Down
23 changes: 12 additions & 11 deletions Cargo.toml
Original file line number Diff line number Diff line change
Expand Up @@ -32,10 +32,10 @@ required-features = ["cli"]
doc = false

[dependencies]
# HTTP framework. `http2`: `serve` answers HTTP/1.1 and HTTP/2 on one port,
# so native gRPC clients share the listener with REST ones.
axum = { version = "0.8", features = ["macros", "http2"] }
tower = "0.5"
# HTTP framework of the proxy's routes; `serve` runs connections on hyper-util.
axum = { version = "0.8", features = ["macros"] }
# `util`: the guarded gRPC and fallback paths are boxed services.
tower = { version = "0.5", features = ["util"] }
tower-http = { version = "0.7", features = ["cors", "trace"] }
# Foundational HTTP types, used directly by the framework-agnostic embedding
# hooks (src/hooks.rs) so an embedder never names `axum`. Already in the tree
Expand All @@ -48,6 +48,9 @@ bytes = "1"
http-body = "1"
# The response futures of `ProxyService`, named without boxing each one.
pin-project-lite = "0.2"
# `serve_with`'s connections: HTTP/1.1 and HTTP/2 on one port, over TCP or
# TLS. Already in the tree through axum and tonic.
hyper-util = { version = "0.1", features = ["server-auto", "service", "tokio"] }

# gRPC client (to upstream service). `tls-connect-info` gives a rustls server
# stream the connection record (client certificates) a tonic handler reads, so
Expand All @@ -57,6 +60,8 @@ pin-project-lite = "0.2"
tonic = { version = "0.14", features = ["tls-connect-info"] }
tokio-rustls = { version = "0.26", default-features = false }
tonic-health = "0.14"
# `grpc_web.translate`: gRPC-Web to gRPC for an upstream that speaks only gRPC.
tonic-web = "0.14"
# Canonical google.rpc.Status / error_details descriptors (FILE_DESCRIPTOR_SET)
# and the Status message used to decode `grpc-status-details-bin`, so REST error
# bodies can render typed details even when the product descriptors do not
Expand Down Expand Up @@ -171,8 +176,10 @@ cli = ["dep:clap", "dep:tracing-subscriber", "redis"]
[dev-dependencies]
# `test-util`: deadline tests run on a paused clock instead of waiting.
tokio = { version = "1", features = ["macros", "rt-multi-thread", "test-util"] }
tower = { version = "0.5", features = ["util"] }
tower = { version = "0.5", features = ["util", "limit"] }
http-body-util = "0.1"
# `hyper::upgrade::on`: a fallback that upgrades its connection (src/serve/tests.rs).
hyper = "1"
# Trailer frames for the hand-written upstream response in
# tests/upstream_controls.rs (tonic's server API cannot set success trailers).
http-body = "1"
Expand All @@ -181,12 +188,6 @@ http-body = "1"
# features would pull in aws-lc.
tokio-rustls = { version = "0.26", default-features = false, features = ["tls12"] }
rustls-rustcrypto = "0.0.2-alpha"
# The embedder-owned TLS server of tests/tls.rs (HTTP/1.1 and HTTP/2 on one
# connection type), and the TLS stream a tonic client dials through.
hyper-util = { version = "0.1", features = ["server-auto", "service", "tokio"] }
# An upstream that speaks gRPC-Web, the way an embedder gives it that
# protocol (tests/edge.rs).
tonic-web = "0.14"
# benches/jwt_verify.rs. Plots and rayon are left out: numbers are enough.
criterion = { version = "0.8", default-features = false, features = ["async_tokio", "cargo_bench_support"] }
# The embedding-hooks integration test (tests/hooks.rs) writes hook impls using
Expand Down
Loading
Loading