Booking.com [2] uses HAProxy for edge delivery over other software load balancers.
Github [3][4] has used it to mitigate DDoS attacks and StackOverflow [5] has used it to detect and protect against bot threats.
Finally, phk, the author of Varnish states [6] (in regards to implementing SSL/TLS): “When I look at something like Willy Tarreau's HAProxy I have a hard time to see any significant opportunity for improvement.”
[1] https://www.haproxy.org/#secu
[2] https://events.static.linuxfound.org/sites/events/files/slid...
[3] https://www.youtube.com/watch?v=xxs7CoLMXt8
[4] https://githubengineering.com/glb-part-2-haproxy-zero-downti...
[5] https://events.static.linuxfound.org/sites/events/files/slid...
I'm still worried about the TLS implementation. I think in your [6] phk considered just incremental improvements, not switching away from C - after all the whole post is about not wanting to implement TLS at all in his own C codebase, having anticipated problems like Heartbleed. (Also at the time of writing, 2015 the Go TLS stack might have been too new to rely on?)
Haskell has yesod[2] but I don't think there's a variant of that dedicated to nginx- or haproxy-esque reverse proxy duties.
But this is not the purpose of the thread.
It’s also customisable in other languages other than Lua (Python, JS, and anything gRPC) ;-)
We also don’t have the concept of proprietary plugins, so where Kong is “Open Core” (for example if you want to use openID connect you need to buy enterprise, with us it’s just par for the course), we bake everything gateway-related into the open source version and don’t hide the ball. Our “value add” is in our dashboard GUI (proprietary) and multi-cloud/multi-DC server (also proprietary).
Also, in Tyk you can model your api routing as a file, with Kong you need to specify all routes as API calls to the gateway, so backing up/version controlling your APIs is difficult without using a community-provided solution. (Though don’t get me wrong, both Tyk Gateway and Dashboard are entirely API driven, so you can do everything programmatically or declaratively).
Lastly - we have a compatability promise of “no breaking changes within major versions”. It’s harder to do, but makes our users happy :-)
Ah, and in terms of extensibility, we provide middleware and event hooks that can be hooked into with any gRPC compatible language and offer native binary (FFI) Support in Python and Lua, we also have a baked in ECMAScript interpreter which is fast (it’s written in Go), but being an interpreter doesn’t have the expressiveness of some of the other extension options)
In terms of other implementations, in open source there’s not many thst have quite the breadth of functionality we offer.
To be fair though, the other solutions out there (especially coming out of the Go/K8s/CNCF communities are very impressive.
One of our users recently did a write up on their experience using us with particular focus on plugins: https://bitsofinfo.wordpress.com/2018/06/28/migrating-to-tyk...
Author: https://github.com/bitsofinfo
And do you want just a gateway or also api management?