Bud – A TLS terminating proxy
github.com
github.com
bud is one of the few node based TLS terminators and easily the best maintained. Modulus (the hosting company) use a Go based implementation. I think Nodejitsu had a node TLS terminator too but I'm not sure what happened to it post-GoDaddy.
memcpy(frame + 12, client->remote.host, client->remote.host_len);
It's 2015. One should not be hand-coding string manipulation at the pointer level.Defensive programming like that is a very good idea especially for something network facing.
If you're sure it's always at most 46 bytes, make it 48 bytes and specify "#define BUD_MAX_HOST_IP_LEN (48)".
Very secure and compiler will probably replace those memcpys with a few SSE [1] instructions, because 48 is a multiply of 16.
Copying 48 bytes is always much faster than copying 1 byte with a dynamic length argument for memcpy.
[1]: Like 6x MOVDQU instructions. Probably interleaved with the rest of the code to hide latency.
If bud was my own pet project, I'd write it in Golang, which is great for networking code. The software I've written so far in Golang has been rock solid, with practically zero defects, in addition to being very understandable and readable code for other people. I wish I could say same of C/C++...
Or maybe in Rust to get a better hang of it. I think Rust will eventually capture a lot of C/C++'s "market share". It should be feasible to write firmware, operating systems and device drivers in Rust.
True, although that was building a binary message, not exactly a string.
"frame" should have probably been a (packed) struct instead of "unsigned char frame[256];".
Bud is written in C, not Node. It uses NPM for cross-platform packaging, but that is optional.
> Is there a feature-based reason to use this over HAProxy or nginx,
It can be useful to have SSL termination be in its own process to isolate OpenSSL from other parts of your internal system like HTTP routing/request handling. For instance, in cases where you have explicit security requirements like FIPS 140-2.
Got it, thanks.
> It can be useful to have SSL termination be in its own process to isolate OpenSSL from other parts of your internal system like HTTP routing/request handling. For instance, in cases where you have explicit security requirements like FIPS 140-2.
Sure. I run two HAProxy instances for that, though.
* Asynchronous SNI - you may load cert/key pairs on the fly and let bud know which backend do you want it to connect the incoming client to
* Asynchronous OCSP stapling
* TLS ticket rotation, with possibility to scale to the big cluster
* x-forward frame for SPDY, and soon for HTTP/2 too
* Lots of other features, but nothing bud-specific