16 ms·
Ferron – A fast, memory-safe web server written in Rust
- frontfor 1y agoAre there benchmarks demonstrating its speed?
- mleonhard 1y agoI'm also interested in looking at the benchmark code.
- no_wizard 1y agoI wonder why they left nginx off their comparisons. Is it simply because nginx is still faster I wonder
- dorianniemiec 1y agoMaybe because of marketing reasons or because I am biased in the comparisons?
- no_wizard 1y agoSo open question: is nginx faster? I think this is really cool. More competition in this space is better not worse, I am merely curious to know how it stacks up
- alexpadula 1y agoYou’re comparing a new project to nginx. Obviously nginx will be faster maybe not across the board but generally it probably is. As a project matures it will optimize surely! nginx has 21 years of development under its belt.
- dijit 1y agoBy that reasoning Apache should be faster than nginx, but alas. https://pressable.com/blog/head-to-head-performance-comparison-of-nginx-and-apache/ https://pressable.com/blog/head-to-head-performance-comparis... I think drawing any conclusions in the absence of benchmarks is unwise.
- MrFurious 1y agoWhat?, apache have mpm_event since many years ago, you don't need prefork process model except if you want use mod_php or something not thread safe.
- graemep 1y agoIt is often a mistake to draw conclusions even with benchmarks. Are the benchmarks measuring what is relevant to your use case? Are the benchmarks unbiased. Your link does not seem to contain any benchmarks anyway. The Ferron benchmarks on their home page say Apache Pre fork MPM outperforms Apache Even MPM which seems odd to me.
- alexpadula 1y agoVery detailed post. True dat.
- yjftsjthsd-h 1y agoEspecially because the details under that say, > The web servers serve a default page that comes with NGINX web server. so yeah, if you even refer to nginx when talking about benchmarks but leave it out, I'm going to favor adverse inference and assume that it's because nginx is faster.
- m00dy 1y agolooks like caddy clone in rust ;) good luck. I think it is way better than caddy. Auto TLS renewal is a banger. I was thinking the same to build but had no time to do it.
- dorianniemiec 1y agoThank you! I think that my web server is indeed similar to a popular Caddy web server.
- password4321 1y agohttps://github.com/errantmind/faf https://github.com/errantmind/faf is the fastest Rust static "web server" per the most recent TechEmpower Round 23 (Plaintext); it is purposely barebones (provide content via Rust callback!) The top 3 Composite scores are all Rust web frameworks, also not necessarily intended as general-purpose web servers. https://github.com/static-web-server/static-web-server https://github.com/static-web-server/static-web-server wins the SEO (and GitHub star) battle, though apparently it is old enough to have a couple unmaintained dependencies. I use https://github.com/sigoden/dufs https://github.com/sigoden/dufs as my personal file transfer Swiss Army knife since it natively supports file uploads; I will check out Ferron as a lighter reverse proxy with automatic SSL certs vs. Caddy.
- dorianniemiec 1y agoStatic Web Server is also old enough to use Hyper 0.14.x instead of Hyper 1.x used by Ferron. I wish you good luck using Ferron then!
- sshine 1y ago> the fastest ... purposely barebones This piece of fiber cable is the fastest static web server. It is purposely barebones, but I bet you, it does almost nothing to reduce the delivery of a static website. The trick is: The website is already in its final state when it gets piped through the fiber cable, so no processing is required. The templating and caching mechanism is left open for most flexibility. I call it an OSI layer 1 web server. The trick is to use fiber instead of copper. Many webservers don't care about this.
- dorianniemiec 1y agoThe author of Ferron web server here. Thank you so much for submitting this, and thank you all for the support you have shown when I submitted the server on Hacker News.
- indeyets 1y agoImportant part of caddy’s configuration are their defaults. For example TLS and automatic certificates are on by default. It covers the most useful use case by default. Ferron is different. Is that a choice or just something you didn’t work on yet?
- dorianniemiec 1y agoWell, Ferron has HTTP/2 and OCSP stapling enabled by default when HTTPS is enabled.
- KennyBlanken 1y agoSome feedback: you really need to put a features list somewhere prominent and tell people what distinguishes your webserver from others in terms of its capabilities. Also, your FAQ really makes you come off as incredibly patronizing.
- dorianniemiec 1y agoWhy do you think that FAQ makes me come off as patronizing?
- tommyage 1y agoI am also wondering about this. To me, your FAQ quickly addressed all questions I had to get a first grasp of the capabilities. It appears to me that you had a determined scope and I very much like that!
- amenhotep 1y agoI wouldn't be as harsh as that, but "what is a web server" feels very out of place in how basic it is, and the final one that basically just says "read the docs" maybe also doesn't quite land.
- alexpadula 1y agoCool project! The first feature put a smile on my face! “Built with rust so it’s fast” paraphrasing but yeah :)
- dorianniemiec 1y agoThank you!
- alexpadula 1y agoYou got it!! Keep it up :). Thank you for posting it
- throwaway81523 1y agoYikes, there is a musician named Ferron who has been around forever, and her web site was formerly ferronweb.com. So I did a double take when I saw this. The musician's web site is ferronsongs.com now. Shadows on a Dime (from 1984) is a great album.
- dorianniemiec 1y agoOh... Good to know!
- eptcyka 1y agoHow does it handle slow loris?
- dorianniemiec 1y agoHyper (HTTP library used by Ferron) has request header timeout of 30s by default if a timer is set. Ferron sets the timer for Hyper for request header timeout to work, thus mitigating Slowloris.
- fatchan 1y agoOffering more detailed timeouts for other stages of the request would be great, too. For example with HAProxy you can configure separate timeouts for just about everything. The time a request is queued (if you exceed the max connections), the time for the connection to establish, the time for the request to be recived, inactivity timeout for the client or server, inactivity timeout for websocket connections... The list goes on: https://docs.haproxy.org/3.1/configuration.html#4-timeout%20check https://docs.haproxy.org/3.1/configuration.html#4-timeout%20... Slowloris is more than just the header timeout. What if the headers are received and the request body is sent, or response consumed very slowly? And even if this is handled with a "safe" default, it must be configurable to cater to a wide range of applications.
- dorianniemiec 1y agoI also implemented timeouts for response processing (including reading the request body from the client), to protect against Slow HTTP POST attacks.
- ngrilly 1y agoIs it configurable?
- liveafterlove 1y agoNice, does it support DTSL for webrtc over the same port? Nginx only have a patch for it ATM.
- dorianniemiec 1y agoThank you! Unfortunately, Ferron doesn't support DTLS, although it can be used as a WebSocket reverse proxy for signaling in WebRTC applications...
- Tepix 1y agoHow much memory does it use? Is it suitable for memory-limited scenarios like a Raspberry Pi 1 with 256MB?
- dorianniemiec 1y agoI am not exactly sure, but comparing Ferron 1.0.0-beta5 and Caddy 2.9.1 in a benchmark where HTTPS, HTTP/2 are enabled, and default Apache httpd page was served, Caddy used so much memory, that at 12,600 requests per second the system with 16 GB RAM ran out of memory, while Ferron didn't use that much memory, and benchmark succeeded up to 20,000 requests per second. Maybe it's a bug in Caddy?
- nicce 1y agoIt also can be Go issue. Garbage collector did not have time to free memory.
- evantbyrne 1y agoEither that or misconfiguration with the benchmark setup. A quick google search indicates this can happen with some setups. Maybe try looking at other Caddy benchmark code.
- nicoburns 1y agoAlmost certainly given that pretty much all Rust webservers are, and this one is built on the same dependencies as others. I run a few websites on fly.io VMs with 256mb using Rust servers that never actually exceed 64mb of usage.
- DoctorOW 1y agoThis is a really good Caddy replacement. The configuration format Caddy uses sometimes feels oversimplified in that complex configurations are hard to read. My instincts tell me this could scale better without getting more verbose. I'm definitely considering a migration if this project matures.
- dorianniemiec 1y agoThank you!
- austin-cheney 1y agoEvery web server claims to be fast, so I wonder how they define that. As someone who has written their own supposedly fast web server I only want configuration simplicity. Most web servers are unnecessarily far too complicated. In a web server here is what I am looking for: * Fast. That is just a matter of streams and pipes. More on this later. That said the language the web server is written in largely irrelevant to its real world performance so long as it can execute low level streams and pipes. * HTTP and WebSocket support. Ideally a web server will support both on the same port. It’s not challenging because you just have to examine the first incoming payload on the connection. * Security. This does not have to be complicated. Let the server administrator define their own security rules and just execute those rules on incoming connections. For everything that fails just destroy the connection. Don’t send any response. * Proxy/reverse proxy support. This is more simple than it sounds. It’s just a pipe to another local existing stream or piping to a new stream opened to a specified location. If authentication is required it can be the same authentication that sits behind the regular 403 HTTP response. The direction of the proxy is just a matter of who pipes to who. * TLS with and without certificate trust. I HATE certificates with extreme anger, especially for localhost connections. A good web server will account for that anger. * File system support. Reading from the file system for a specific resource by name should be a low level stream via file descriptor piped back to the response. If this specific file system resource is something internally required by the application, like a default homepage it should be read only once and then forever fetched from memory by variable name. Displaying file system resources, like a directory listing, doesn’t have to be slow or primitive or brittle.
- xorcist 1y agoMost of these things are much harder to get right that you make it sound. Perhaps proxying most so. It is a legitimately hard problem. Look at something like Varnish, which is likely one of the better proxies out there. It took many years to get good. I never had to write a proxy and am grateful for it. You have to really understand the whole network stack, window sizes and the effects of buffering, what to do about in flight requests, and so on. Just sending stuff from the file system is comparatively easier where you have things such as sendfile, provided you get the security implications of file paths right.
- 1y ago
- wildinprogress 1y ago[dead]
- timeflex 1y agoThe first thing on their main homepage is instructions to curl a shell script into Bash using Sudo. I find the argument that they prioritize security unconvincing.
- dorianniemiec 1y agoOh... For safety, it's recommended to check the installation script for suspicious commands. Or you can just pull the image for the Ferron web server from Docker Hub.
- timeflex 1y agoYou mean the script that you'd have to check every time you want to install? At least with Docker, unless you're running the container privileged then you have some isolation. However, a package manager is usually the recommended approach since those apps are usually checked by maintainers & often routinely scanned for vulnerabilities. A package manager is my preferred approach.
- echoangle 1y agoJust for arguments sake, how did you install docker engine? Did you add their apt source where they can push anything they like into their packages? And also, you shouldn’t rely on docker for safety, it might or might not work but docker isn’t a reason to just run an untrusted program.
- timeflex 1y agoI'm not even using Docker. I use Podman in rootless mode installed using the system package manager. Even if an app found a way to break out of the container, it wouldn't have elevated privileges. I'm not saying security is about perfection, but encouraging people to curl something to the shell with sudo is poor practice. I get that it is a newer piece of software, so I am forgiving. But getting it packaged into Homebrew, WinGet, Nix, etc. is more ideal. Some of them may verify a signed package, ensure reproducible builds, track changes for proper uninstalls, etc.
- nottorp 1y agoIsn't Go better for writing servers, and as fast and memory safe as the second coming of $DEITY?
- dorianniemiec 1y agoGo has larger ecosystem of libraries for building web servers. You have FrankenPHP for running PHP, Lego for automatic TLS, etc. For Rust there is `tokio-rustls-acme` crate (used by Ferron) for automatic TLS. While for PHP there is a `php` crate that depends on unsupported PHP version. Ferron uses FastCGI for communicating with PHP-FPM daemon instead. However, Go uses a garbage collector, unlike Rust, which has a borrow checker to ensure memory safety.
- rc00 1y agoRust has garbage collection.
- dorianniemiec 1y agoHow? I rather think that it uses a borrow checker with ownership and borrowing rules.
- dankobgd 1y agono it doesn't
- kapilvt 1y agoDocs links lead to a 403 forbidden for me https://www.ferronweb.org/docs/ https://www.ferronweb.org/docs/
- dorianniemiec 1y agoYou went to the documentation page while I was uploading the website files after I updated the website. You can now refresh the documentation page.
- titaphraz 1y agoKudos. It would have been nice to see benchmarks compared to Nginx, since it's extremely popular. I'm not using any of the other servers in the benchmark so it's meaningless to me.
- dorianniemiec 1y agoThank you!
- bitbasher 1y agoWhy no benchmarks against Nginx?
- arnath 1y agoRandom thing I’ve been wondering: is there a point in including TLS support in web servers any more? Isn’t it always better to run a reverse proxy and terminate HTTPs at the edge?
- dorianniemiec 1y agoThe problem is that you will have more moving parts - a web server, and an additional reverse proxy (which can add overhead). Also, Ferron can also be configured as a reverse proxy.
- yencabulator 1y agoFor many uses, the reverse proxy is the cloud load balancer. That's probably what the grandparent is thinking too.
- shim__ 1y agoThe web Server is the reverse proxy allowing the upstream to be plain http
- rurban 1y agoDid they prove for 100% memory safety or just the default 70% rust memory safety? No, they didnt