Cowboy 2.0 released
ninenines.eu
ninenines.eu
= Cowboy
Cowboy is a small, fast and modern HTTP server for Erlang/OTP.
== Goals
Cowboy aims to provide a complete HTTP stack in a small code base. It is optimized for low latency and low memory usage, in part because it uses binary strings.
Cowboy provides routing capabilities, selectively dispatching requests to handlers written in Erlang.
Because it uses Ranch for managing connections, Cowboy can easily be embedded in any other application.
Cowboy is clean and well tested Erlang code.
== Online documentation
* https://ninenines.eu/docs/en/cowboy/2.0/guide[User guide] * https://ninenines.eu/docs/en/cowboy/2.0/manual[Function reference]
== Offline documentation
* While still online, run `make docs` * User guide available in `doc/` in PDF and HTML formats * Function reference man pages available in `doc/man3/` and `doc/man7/` * Run `make install-docs` to install man pages on your system * Full documentation in Asciidoc available in `doc/src/` * Examples available in `examples/`
== Getting help
* Official IRC Channel: #ninenines on irc.freenode.net * https://github.com/ninenines/cowboy/issues[Issues tracker] * https://ninenines.eu/services[Commercial Support]
It could really use this line on the linked page for people (me) that never heard of Cowboy in the first place. HTTP/2.0 gave me a clue, but plenty of client software that has HTTP/2.0 support too.
[ed: moved the link up, for less confusing flow] http://erlang.org/doc/apps/ssl/ssl_protocol.html#id61195
which isn't all that enlightening to someone not familiar with Erlang. Does anyone know of a "best security practices" particularly for cowboy/opp/erlang and/or elixir?
I'm reminded of how for the longest time ssl was completely broken in python (it wasn't at all obvious how to force verification of certificates - especially for new developers)... And I've grudgingly come to accept that tls/http2 is complex enough that beyond getting to "it works" - even foolproof libraries need a couple of lines of text discussing trade-offs (eg. security vs performance vs ease-of multi-server deployment of session resumption).
There's certainly a lot of room for improved documentation in this area. I'd even buy a book on this topic.
Do a lot of people that run Phoenix apps in production expose cowboy directly to the public?
I'm always putting them either behind nginx or Amazon ALB, both of which support http/2.
Since it's built as an OTP application, it's pretty easy to drop this into any release, including something built using Elixir (commonly via Plug), LFE, Alpaca, and/or plain Erlang.
I'm in awe at the achievement, and combination of vision, drive, knowledge, and skills that the maintainer must possess (or even more inspiring: has built up along the way).
I dread the bus factor[0], or the more common weaker form of "maintainer is forced to move on from this project or just loses interest before someone else takes over and is worked in, and a lot of necessary tacit knowledge[1] is lost in the hand-over".
EDIT: Actually, I'm one to talk, working as the sole programmer at a research group... Given the required optimizations for its niche my code gets pretty hairy. I should plan a few weeks of pure cleanup and extra commenting, and general documentation.
https://ninenines.eu/articles/cowboy-2.0.0/
Full changes: https://ninenines.eu/docs/en/cowboy/2.0/guide/migrating_from...
By the power of grayskull I invoke dang to update the link.