BareProxy: A Reverse Proxy You Can Understand and Own Without Vendor Lock-In
Bootstrapped founders know the math: every service you pay for is a monthly line item that has to be justified by revenue. The reverse proxy sits in front of your whole business, so it has to be reliable, but you don’t want to pay for a managed service you don’t need. You also don’t want to spend months learning nginx config syntax only to discover nobody on your team understands what you built.
BareProxy is built for teams that want to own their infrastructure without the complexity tax. It does what you actually need: TLS termination from Let’s Encrypt, serving static files, routing traffic to your app, health checks. It does not do regular expressions or scripting, which is the point. If you can’t reason about your routing rules, you can’t run your business confidently.
That constraint is a feature. Every matcher in your config is an exact value, a prefix, or a set. That means your requests fall into a finite number of classes, and the server can enumerate them all. Before a config change goes live, bareproxy plan shows you which existing requests would change hands. If you wrote a rule that can never match, you get a warning. If a change would silently flip traffic to the wrong backend, you see it.
bareproxy explain takes a URL and shows which rule matched it, which file or backend would serve it, and why the rules above it didn’t match. You’re debugging a customer report, and you ask the proxy to show you what it saw. The answer is plain English, not a trace you have to parse. For a founder managing infrastructure solo, this is the difference between sleeping soundly and being on call for mysterious 404s.
bareproxy why tells the story of a request that already happened, starting from the ID in a response header. Your customer says they got a 502 at 3 PM. You pull that header from your logs, pass it to the tool, and the proxy walks you back through which rules matched and which decisions were made. You know what happened, not what you’re guessing.
For bootstrapped companies, the cost story is clear. BareProxy serves your static content directly, with TLS certificates from Let’s Encrypt. You don’t pay per-request or per-gigabyte. You don’t rent a managed proxy. You run BareProxy on a machine you control. The core is 5,000 lines of Go with no external dependencies. You own it, understand it, and can modify it if you need to.
Add functionality as your business grows. Caching headers, rate limiting, request inspection, custom responses are modules that compile in only when you need them. You start with the minimum and add features as revenue justifies them. That’s the bootstrapper’s way: pay for complexity only when the business demands it.
BareProxy is at version 0.1. The design budgets are under 5,000 lines in the core and no external dependencies. Performance against nginx is coming next. The demo page shows each command’s output on a sample config you can read and modify.
For bootstrapped founders, the appeal is sovereignty. You understand your routing rules. Changes are safe because you can see the impact before they run. You own the infrastructure instead of renting it. A reverse proxy that you can reason about, that costs nothing to run, and that doesn’t lock you into a vendor is the difference between a business that scales sustainably and one that’s perpetually dependent on expensive tooling. BareProxy is built for founders who want to own their path.