14 ms·
High Performance TCP Proxy Server
- brudgers 9y agoIf it meets the guidelines, this might make a good 'Show HN'. Show HN guidelines: https://news.ycombinator.com/showhn.html https://news.ycombinator.com/showhn.html
- shouldbworking 9y agoI felt kinda bad tearing it apart and only did so because it wasn't posted as a ShowHN. It's cool to show people an example of networking using Boost but the article and post have no mention of this being alpha quality software.
- brudgers 9y agoMaybe the author was proud of shipping.
- venture_lol 9y agoDarn...opening 2 sockets, read from one and write to the other, that qualifies as "show me mama...no hands" :) ?
- shouldbworking 9y agoIt blows my mind that this is on the front page. It's not useful for anything, doesn't fully work, and can be replicated with a few lines on the console of BSD/Linux/windows.
- venture_lol 9y agoReminds of the time a friend wanted my opinion on a quote he received that it would take a week to open a socket in Unix using C code
- shouldbworking 9y agoSounds about right. Takes even longer to close it. That's why you don't manage the socket yourself and just use boost ;)
- throwaway2016a 9y agoHow does this compare to using HAProxy in TCP mode?
- matthewaveryusa 9y agoHAProxy is 90k loc while this is 300 loc so they really are different beasts. I would say HAPRoxy is a great general purpose proxy that has most of the features you want while this proxy server is a MVP proxy you can grow off of if you want to do something that HAProxy can't provide.
- shouldbworking 9y agoNetty is a more mature foundation for this sort of thing and likely much faster
- acdha 9y agoCan you expand on your reasons for making that claim - perhaps with some benchmarks?
- shouldbworking 9y agoCheck out the techempower framework benchmarks. Netty can do over a million http responses per second on a reasonable machine. On Linux it uses an epoll native driver and is asynchronous. The framework makes it possible to write proxies in a few lines. If you want to beat netty by a significant margin you'll probably need to use kernel bypass
- jithesh 9y agoC++ 17 Networking TS is based on ASIO. It will be very interesting if netty performs better than ASIO based code for the same task.
- 9y ago
- matthewaveryusa 9y agoAs a sidenote if you don't have a requirement to compile with C++03 I would recommend using the standalone asio library free from boost[1]. The only things you need to modify are the includes and namespaces. [1] http://think-async.com/Asio/Download http://think-async.com/Asio/Download
- inetknght 9y agoWhy would you recommend the upstream Asio library instead of the one in Boost?
- matthewaveryusa 9y agoBecause it has zero dependencies -- There's no reason to pull in boost::shared_ptr when you can use std::shared_ptr
- signa11 9y agoare there benchmarks also available ? may you please share them for objective comparison with other implementations. thank you!
- huhtenberg 9y agoVery nice, but this is more of a demo code for boost::asio than something that is production-worthy. For example, it doesn't relay FINs between connections, doesn't disable Nagle algorithm on the upstream socket, doesn't wait for pending writes to complete before tearing down the connection, doesn't handle congestion at all (potentially leading to unbound memory use), etc.
- pacmanfan 9y agoCould you point to an open source TCP proxy that you'd consider production worthy with an approachable code base?
- jonhohle 9y agohttp://nginx.org http://nginx.org
- pacmanfan 9y agoI assumed (without looking) that because of all of the features, the nginx codebase wouldn't be that east to read. I'll give it a try!
- LoSboccacc 9y agohaproxy is quite well documented
- toast0 9y agostud is pretty approachable and production worthy; I assume hitch [1] remains so, if you dropped the TLS termination, it would just be a TCP proxy as well. [1] https://hitch-tls.org/ https://hitch-tls.org/
- user5994461 9y agoHAProxy is the gold standard. nginx and apache only do HTTP(S). Don't support TCP.
- 9y ago
- userbinator 9y agoAs someone who has also written a TCP proxy (along with many others...), after thoroughly reading the page I'm still unsure of how exactly this is "high performance". It is also curious that, despite the fact that it uses a separate library for networking, the source is already quite a bit longer than some other proxies which don't. I found the explanation overly complex. Around half the code in this implementation could probably be removed by the realisation that, after a connection is established, both ends are completely symmetric: all it needs to do is try to read from A and write to B, then try to read from B and write to A. If A closes, close B. If B closes, close A.
- zzzcpan 9y ago> If A closes, close B. If B closes, close A. It's shutdown() writes on EOFs, not close, with refcounting to also do close() when EOFs were detected on both directions (I also have written a TCP proxy). But yeah, TCP proxies are trivial, would be more interesting to see something like a tunneling proxy that sends data over multiple connections to maximize performance.
- tlarkworthy 9y agoHey, I am looking for a way of packing multiple TCP streams over a single TCP connection to a backend server. I can unpack them in application logic if necessary. Do you know what that is called? Kinda like SCTP
- RickHull 9y agoMultiplexing?
- tyingq 9y agoThe quick and dirty approach would be an ssh tunnel or vpn. There's also GRE tunnels which would be faster, but not encrypted. Any of these would work without having to change the application. Probably, though, it's best to start with why you would want to do that. You could be, for example, trying to solve something where a pub/sub model would work better. Or just two separate apps, on different ports. What's driving the idea of multiplexing?
- deleted 9y ago[deleted]
- larvaetron 9y agoA similar application that I'm fond of is Pen, which also does simple load balancing and has udp support: http://siag.nu/pen/ http://siag.nu/pen/
- mdekkers 9y agoIronically, the site appears down (I am redirected to google)
- tawan 9y agoYep,I second that. I'm getting redirected to google.
- petethepig 9y agoI thought it was some kind of a joke. I guess you could say that google.com is a high performance tcp proxy server.
- TheGuyWhoCodes 9y agoI got redirected when using chrome but not on firefox.
- adontz 9y agoWhy not just? Linux: iptables -t nat -A PREROUTING -p tcp -s 192.168.20.200/0 -d 192.168.0.100/0 --dport 8080 -j REDIRECT --to-ports 20000 Windows: netsh interface portproxy add v4tov4 listenaddress=192.168.20.200 listenport=8080 connectaddress=192.168.0.100 connectport=20000 protocol=tcp
- paulddraper 9y agoThose require root/admin access. Still, I agree.
- wmf 9y agoBecause people don't learn the OS.
- AReallyGoodName 9y agoSocat is excellent too. Not as high performance as iptables but the command is very simple to use. More of a direct replacement for the program above.
- eps 9y agoBecause it's not as interesting :)
- user5994461 9y ago-s 192.168.20.200/0 -d 192.168.0.100/0 That sounds wrong. You probably meant /24 or /32. Or you meant to not write anything to not filter it at all.
- adontz 9y agoYeah, sorry for that, was copy-pasting too quickly :-)
- snczl 9y agoOr use the layer-4 load balancer built into the Linux kernel - IPVS (http://kb.linuxvirtualserver.org/wiki/IPVS http://kb.linuxvirtualserver.org/wiki/IPVS). Use Keepalived (http://www.keepalived.org/ http://www.keepalived.org/) for HA and health checking or use Gorb (https://github.com/kobolog/gorb https://github.com/kobolog/gorb) and you can dynamically change services / backends using a REST API.