6 ms·
To tell you the truth, we didn't consider it. From what I can get from the architecture docs[1], it can be a decent platform for apps, but might not be the bes
by SaveTheRbtz 6y ago
To tell you the truth, we didn't consider it. From what I can get from the architecture docs[1], it can be a decent platform for apps, but might not be the best choice for a general purpose ingress/egress proxy (at least for now.)
[1] https://caddyserver.com/docs/architecture https://caddyserver.com/docs/architecture
- mholt 6y agoIt is a great choice for a general purpose proxy. (That's kind of the point.)
- atonse 6y agoBut they mentioned that they wanted to use C++ instead of go to get even that extra performance out. I use Caddy a lot and it's perfectly fine for my scale, but at dropbox's scale, maybe go wouldn't be enough for the ingress part?
- mholt 6y agoI just lament the increasing deployments of programs written in memory-unsafe languages to the edge, in general. I am more curious what makes the author think Caddy "might not be the best choice for a general purpose ingress/egress proxy" (there were no other qualifications to that statement, but no evidence to support it either).
- mperham 6y agoYeah, to its credit, the article brought it up but then kinda hand waved away "envoy had many more security issues than nginx". Having a huge load of C library dependencies in a user-facing service seems like a bug these days. Part of reducing dependencies in my own software was a conscious decision to minimize future CVE exposure.
- DarkWiiPlayer 6y ago> C++ instead of go to get even that extra performance out Might as well use C then (with some hand-written asm sprinkled in where the compiler gets confused and doesn't see an obvious optimization) for that. And I'm not even being sarcastic here (I wish I was though)