Changelog
All notable changes to ferryman-edge-core and ferryman-edge (the proxy).
Both crates share one version. Format follows
Keep a Changelog; versions follow
SemVer (pre-1.0: minor bumps may break).
Unreleased
0.1.1 — 2026-09-30
No code changes in either crate.
Added
- Reference examples, built and run in CI:
examples/edge-demo(the proxy in front of sample services, 55 end-to-end checks, and a docker-compose topology with Prometheus) andexamples/embed-core(ferryman-edge-core inside an axum service). - Project guide at https://bunty9.github.io/ferryman-edge/ (now the crates’ homepage).
Changed
- Releases are published from CI through crates.io Trusted Publishing (OIDC); no long-lived API token is used.
- READMEs: install section, crates.io / docs.rs badges.
Fixed
- Docker image: builder pinned to bookworm to match the distroless runtime’s
glibc;
.dockerignorekeepstarget/and keys out of the build context.
0.1.0 — 2026-09-28
Added
- mTLS termination on rustls 0.23 + aws-lc-rs; client certs required and chained to a configured CA bundle; ALPN h2 / http/1.1.
- RS256 JWT auth with a moka cache;
expre-checked on cache hits,nbfenforced, optionaliss/aud. - Per-tenant GCRA rate limiting keyed by JWT
sub(tenant_rps = 0disables it). - Segment-boundary longest-prefix routing with a lock-free Closed / Open / HalfOpen circuit breaker per upstream and an active health checker.
- SIGUSR1 hot reload of TLS material and routes without dropping connections; breaker state kept for unchanged routes.
- Graceful drain on SIGTERM / SIGINT.
boxed_bodyfeature: stream request and response bodies instead of collecting them.- Prometheus metrics (requests, auth failures, rate limiting, TLS handshakes, breaker state, upstream health).