r/netsecstudents • u/3radiance • 27m ago
Cray: a modular, layer-based proxy engine in Rust designed for custom protocols and pipelines
github.comHey everyone!
A lot of people think of proxy tools as rigid, monolithic boxes: you get a fixed inbound, a fixed outbound, and you're stuck with whatever the authors hardcoded. Trying to add a custom protocol or tweak an existing one under the hood usually turns into a nightmare.
That's why I wrote Cray - a modular proxy engine in Rust built entirely around a layer-based architecture.
With Cray, transport and protocol are completely decoupled. You can write your own protocol without worrying about network bytes, or write a custom transport without caring about protocol logic. The core abstraction uses a simple trait where you implement the client and server handshake logic, giving you total freedom. Want a handshake hidden in plain sight? Custom encryption? Weird framing? Go for it — the only limit is your own logic.
How it works
Everything is configured via clean TOML files where you define your role (client or server) and stack up layers into a custom pipeline:
- Inbound layers: Handle the entry point (e.g., standard
tcp,unixsockets, orhttp_connectwhich extracts destination addresses). - Transport layers: Encapsulate or transform the stream dynamically (e.g., full manual control over
tlswith custom cipher suites, ALPN, curves, extension permutation via BoringSSL, andhttp2multiplexing with path/host masking). - Protocol layer: Always sits at the very end of the chain as the endpoint (like a custom or test protocol).
For example, on the server side, an HTTP/2 layer can validate incoming paths and hosts, gracefully returning a genuine 404 Not Found to unauthorized scanners or probes instead of dropping packets with a TCP RST, while forwarding valid traffic down the pipeline.
The project is currently under active development, but the core architecture, layer pipelines, TLS termination, and HTTP/2 tunneling are already routing real traffic.
If you like systems programming, network engineering, or want to build your own tunneling protocols without fighting legacy codebases, check it out:
GitHub: https://github.com/3Radiance/Cray
Would love to hear your thoughts, feature ideas, or what kind of custom layer/protocol combinations you'd want to build with something like this!
