Why we picked WireGuard, and what we'd do differently.
Three years in, the protocol still feels right. The control plane around it is what we'd rebuild.
Engineering posts, architecture writeups, and the occasional opinion. Written by people who run the proxy.
A walk through the architecture of our hottest path — from QUIC ingress to the WebAssembly sandbox and back. Where we cheated, where we didn't, and the three benchmarks that lied to us.
Three years in, the protocol still feels right. The control plane around it is what we'd rebuild.
Most production middleware is a header rewrite, a cookie parse, and a redirect. Make those one-line filters first.
Why we put $0.05/GB and $1/M on the homepage instead of "Contact sales." A short post on aligning incentives.
A field report from teams who migrated off Ingress in 2023. What stuck. What broke. What we'd warn you about.
How we replaced four different log formats with one OpenTelemetry pipeline. Spoiler: it took longer than we said it would.
Sidecars solved a real problem in 2018. The cost surface they leave behind is harder to defend in 2026. Here's our take.
We measured 200ms cold starts and asked: where is the time actually going? Most of it isn't where you'd guess.
A review of the gnarly bits — congestion control, MTU discovery, and what happens when the middlebox lies about UDP.
A small DSL we wrote so platform teams stop writing 80-character regex predicates and instead write three readable lines.
Engineering writeups, architecture posts, and the occasional opinion — delivered by email. Unsubscribe in one click.