Most reverse proxies hide their decisions. A request comes in, traffic flows somewhere, and if it goes to the wrong place, you read logs trying to work backwards through regex matching and conditional logic. The configuration is so complex that nobody is quite sure which block handles a given URL, and changes are made nervously because the impact is hard to predict.
BareProxy is built on a radical constraint: no regular expressions, no scripting. Every matcher in your config is an exact value, a prefix, or a set. With that limitation, the requests your site can receive fall into a finite number of classes, and the server can enumerate them all.
That foundation pays off technically in three commands. bareproxy explain takes a URL and shows which rule matched it, which file or backend would serve it, and why the rules above it didn’t match. The output is deterministic—you get the same answer every time for the same input, and that answer is mathematically derivable from the config.
bareproxy why tells the story of a request that already happened, starting from the ID it carried in a response header. You ask the server to walk back through exactly which rules matched, which decisions were made, in order. For a system that’s supposed to be transparent, this is what transparency looks like.
The technical innovation is bareproxy plan. Before a config goes live, it compares the new file with the running one and enumerates which existing requests would change hands. If you’ve written a rule that can never match because an earlier rule takes all its traffic, you get a warning. If a change would silently flip traffic between backends, you see it. This is possible because there are no regular expressions to be ambiguous about—each request class is known.
For static sites the core serves a folder directly, with TLS certificates from Let’s Encrypt. Caching headers, rate limits, request inspection, and custom responses are modules that compile in only when you need them. The core is 5,000 lines of Go with no external dependencies.
BareProxy is at version 0.1. The design budgets are under 5,000 lines in the core, no dependencies from outside the Go project, and performance measurements against nginx coming next. The demo page shows each command’s output on a sample config.
The technical appeal is clarity: you can reason about routing because the constraints that make it hard have been removed. For infrastructure engineers who care about understanding the systems they run, a reverse proxy that is provably correct by construction is a rare find. The innovation is not in performance or features, but in making a boring tool transparent enough that you can trust it.