A purpose-built proxy for the Linkerd service mesh. Written in Rust.
Go to file
Oliver Gould 26b718c55d
Include server address in server error logs (#2500)
When the proxy's TCP server encounters an error (usually due to one of
the connections failing, we log the error and the client's address. The
server's address was omitted because it varies based on context that is
not known in this module: in some cases it's the actual server address
on the socket, but when proxying a connection it may be determined by
the value retrieved from the SO_ORIGINAL_DST socket option.

To fix this, the server now requires that connection metadata be able to
materialize an 'AddrPair' parameter that describes a client-server
connection. The TCP listener impls are updated to satisfy this based on
the appropriate metadata; and the TCP server consumes this type to
include both client and server addresses in the relevant logs/contexts.
2023-11-03 10:30:25 -07:00
.checksec release: Produce static binaries (#2057) 2022-12-12 16:10:11 -08:00
.devcontainer dev: Update to Rust v1.69.0 (#2402) 2023-04-25 15:56:34 -07:00
.github chore: change `rust-toolchain` file to toml format (#2487) 2023-10-23 10:26:19 -07:00
.vscode chore: change `rust-toolchain` file to toml format (#2487) 2023-10-23 10:26:19 -07:00
docs ci: Lint markdown files (#1707) 2022-05-25 11:46:19 -07:00
hyper-balance Make all comment delimeters uniform (#2120) 2023-01-04 19:00:18 -08:00
linkerd Include server address in server error logs (#2500) 2023-11-03 10:30:25 -07:00
linkerd2-proxy Emit distinguishable version info (#2432) 2023-06-23 14:21:28 -07:00
opencensus-proto dev: Update to Rust v1.69.0 (#2402) 2023-04-25 15:56:34 -07:00
tools chore: update `tonic`, `prost`, and `proxy-api` (#1868) 2022-08-05 10:00:40 -07:00
.clippy.toml clippy: Disallow lock and instant types from `std` (#1458) 2022-02-02 11:59:03 -08:00
.dockerignore Add proxy_build_info metric (#600) 2020-07-24 09:19:40 -07:00
.gitattributes Update to linkerd2-proxy-api v0.5 and tonic v0.7 (#1596) 2022-04-11 11:29:33 -07:00
.gitignore fuzz: Omit lockfiles from version control (#1088) 2021-06-16 17:08:16 -07:00
CONTRIBUTING.md dev: Update markdowlint-cli2 to 5.0.1 (#1892) 2022-08-15 13:42:18 -07:00
Cargo.lock inbound: Fix gRPC response classification (#2496) 2023-11-01 17:41:19 -07:00
Cargo.toml meshtls: use published `rustls-webpki` v0.101.5 (#2470) 2023-09-18 11:13:11 -07:00
DCO Add contributing doc and DCO file (#88) 2017-12-22 14:54:27 -08:00
Dockerfile Emit distinguishable version info (#2432) 2023-06-23 14:21:28 -07:00
GOVERNANCE.md ci: Lint markdown files (#1707) 2022-05-25 11:46:19 -07:00
LICENSE Introducing Conduit, the ultralight service mesh 2017-12-05 00:24:55 +00:00
MAINTAINERS.md ci: Lint markdown files (#1707) 2022-05-25 11:46:19 -07:00
README.md README: comment just-cargo and make it more clear (#2292) 2023-03-07 13:07:35 -08:00
deny.toml Bump ahash to v0.8.5 (#2498) 2023-11-01 12:29:47 -07:00
justfile Emit distinguishable version info (#2432) 2023-06-23 14:21:28 -07:00
rust-toolchain.toml chore: change `rust-toolchain` file to toml format (#2487) 2023-10-23 10:26:19 -07:00

README.md

The Linkerd Proxy

linkerd2

GitHub license Slack Status

This repo contains the transparent proxy component of Linkerd2. While the Linkerd2 proxy is heavily influenced by the Linkerd 1.X proxy, it comprises an entirely new codebase implemented in the Rust programming language.

This proxy's features include:

  • Transparent, zero-config proxying for HTTP, HTTP/2, and arbitrary TCP protocols.
  • Automatic Prometheus metrics export for HTTP and TCP traffic;
  • Transparent, zero-config WebSocket proxying;
  • Automatic, latency-aware, layer-7 load balancing;
  • Automatic layer-4 load balancing for non-HTTP traffic;
  • Automatic TLS (experimental);
  • An on-demand diagnostic tap API.

This proxy is primarily intended to run on Linux in containerized environments like Kubernetes, though it may also work on other Unix-like systems (like macOS).

The proxy supports service discovery via DNS and the linkerd2 Destination gRPC API.

The Linkerd project is hosted by the Cloud Native Computing Foundation (CNCF).

Building the project

We use just-cargo which provide a thin wrapper around just and cargo.

We recommend that you use the included Dev Container to avoid setting up the complex development environment by hand.

Just

A justfile is provided to automate most build tasks. It provides the following recipes:

  • just build -- Compiles the proxy on your local system using cargo
  • just test -- Runs unit and integration tests on your local system using cargo
  • just docker -- Builds a Docker container image that can be used for testing.

Cargo

Usually, Cargo, Rust's package manager, is used to build and test this project. If you don't have Cargo installed, we suggest getting it via https://rustup.rs/.

Devcontainer

A Devcontainer is provided for use with Visual Studio Code. It includes all of the tooling needed to build and test the proxy.

Repository Structure

This project is broken into many small libraries, or crates, so that components may be compiled & tested independently. The following crate targets are especially important:

Code of conduct

This project is for everyone. We ask that our users and contributors take a few minutes to review our code of conduct.

Security

We test our code by way of fuzzing and this is described in FUZZING.md.

A third party security audit focused on fuzzing Linkerd2-proxy was performed by Ada Logics in 2021. The full report is available here.

License

linkerd2-proxy is copyright 2018 the linkerd2-proxy authors. All rights reserved.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use these files except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.