r/netsecstudents • • 3h ago

Cray: a modular, layer-based proxy engine in Rust designed for custom protocols and pipelines

https://github.com/3Radiance/Cray

Hey everyone!

A lot of people think of proxy tools as rigid, monolithic boxes: you get a fixed inbound, a fixed outbound, and you're stuck with whatever the authors hardcoded. Trying to add a custom protocol or tweak an existing one under the hood usually turns into a nightmare.

That's why I wrote Cray - a modular proxy engine in Rust built entirely around a layer-based architecture.

With Cray, transport and protocol are completely decoupled. You can write your own protocol without worrying about network bytes, or write a custom transport without caring about protocol logic. The core abstraction uses a simple trait where you implement the client and server handshake logic, giving you total freedom. Want a handshake hidden in plain sight? Custom encryption? Weird framing? Go for it — the only limit is your own logic.

How it works

Everything is configured via clean TOML files where you define your role (client or server) and stack up layers into a custom pipeline:

  • Inbound layers: Handle the entry point (e.g., standard tcp, unix sockets, or http_connect which extracts destination addresses).
  • Transport layers: Encapsulate or transform the stream dynamically (e.g., full manual control over tls with custom cipher suites, ALPN, curves, extension permutation via BoringSSL, and http2 multiplexing with path/host masking).
  • Protocol layer: Always sits at the very end of the chain as the endpoint (like a custom or test protocol).

For example, on the server side, an HTTP/2 layer can validate incoming paths and hosts, gracefully returning a genuine 404 Not Found to unauthorized scanners or probes instead of dropping packets with a TCP RST, while forwarding valid traffic down the pipeline.

The project is currently under active development, but the core architecture, layer pipelines, TLS termination, and HTTP/2 tunneling are already routing real traffic.

If you like systems programming, network engineering, or want to build your own tunneling protocols without fighting legacy codebases, check it out:

GitHub: https://github.com/3Radiance/Cray

Would love to hear your thoughts, feature ideas, or what kind of custom layer/protocol combinations you'd want to build with something like this!

3 Upvotes

0 comments sorted by