API Gateway. AI Gateway.
Service Mesh.
One Rust-Powered Binary.
Every protocol. 80+ built-in plugins. Eight operating modes.
Ferrum Edge is a high-performance edge platform engineered in Rust. Route, secure, and observe HTTP, gRPC, WebSocket, TCP, and UDP traffic — govern LLM and agent traffic across 11 AI providers — and run a SPIFFE-identity service mesh, all from a single gateway binary.
Three Products in One Binary
Most teams run separate software for API management, AI traffic governance, and service-to-service networking. Ferrum Edge consolidates all three — same binary, same configuration model, same plugins.
API Gateway
Dynamic routing, 10+ authentication methods, rate limiting, WAF threat detection, transformation, caching, and full-stack observability for HTTP/1.1 through HTTP/3, gRPC, WebSocket, TCP, and UDP — with zero-downtime configuration reloads.
AI Gateway
One OpenAI-compatible endpoint routing buffered requests to 11 providers. Streaming is opt-in for supported providers; fallback stops once a streaming provider is committed. Token budgets, semantic caching, prompt firewalls, PII redaction, tool-call governance, compliance transcripts — plus dedicated MCP and Agent-to-Agent gateways for agent traffic.
Service Mesh
Six mesh topologies — sidecar, ambient, waypoints, east-west, and egress gateways — with SPIFFE identity, mutual TLS, HBONE, transparent DNS, mesh authorization policy, and Istio/Gateway API compatibility on Kubernetes.
Up and Running in Minutes
Edge remains pre-1.0. Pin an explicit version tag like v0.9.10 for reproducible installs —
see releases for upgrade notes and companion-tool compatibility.
# Download, verify, and install v0.9.10 for Linux x86_64 (glibc 2.34+).
# Other platforms: use the matching block in the install guides.
ASSET=ferrum-edge-linux-x86_64
BASE=https://github.com/ferrum-edge/ferrum-edge/releases/download/v0.9.10
curl -fsSLO "$BASE/$ASSET" &&
curl -fsSLO "$BASE/$ASSET.sha256" &&
sha256sum -c "$ASSET.sha256" &&
sudo install -m 0755 "$ASSET" /usr/local/bin/ferrum-edge &&
/usr/local/bin/ferrum-edge version
# Create a minimal config that proxies /api to a backend on localhost:3000
cat > config.yaml << 'EOF'
version: "1"
proxies:
- id: "my-api"
listen_path: "/api"
backend_scheme: http
backend_host: "localhost"
backend_port: 3000
strip_listen_path: true
plugin_configs: []
EOF
# Validate, then start Ferrum Edge in the foreground (file mode is inferred from --spec)
ferrum-edge validate --spec config.yaml &&
ferrum-edge run --spec config.yaml -v
A failed download or checksum stops the chain before anything is installed. The gateway keeps running in the foreground, and the sample route expects a backend on localhost:3000; the
Linux and macOS guides continue from here with a throwaway test backend, a liveness check, and a real proxied request from a second terminal.
Everything You Need at the Edge
Ferrum Edge is engineered from the ground up for speed and reliability — no garbage-collector pauses, no lock contention on configuration reads, no compromises.
Lock-Free Configuration Reads
Requests never wait in line to read configuration. Config updates are atomic swaps — in-flight requests finish on the old config while new requests instantly see the new one. Zero downtime, zero stalls.
80+ Built-in Plugins
Authentication, authorization, OPA policy, WAF, rate limiting, adaptive concurrency, AI/LLM governance, transformation, chaos testing, chargeback, and observability — all first-class, all priority-ordered, no marketplace required.
True Multi-Protocol
HTTP/1.1 through HTTP/3 QUIC, WebSocket over all three HTTP versions, gRPC and gRPC-Web, SSE streaming, raw TCP and UDP with TLS/DTLS termination, origination, or passthrough. One gateway, every protocol.
Full AI Traffic Governance
14 AI-focused plugins: provider federation with streaming, token-aware rate limiting, semantic firewall and cache, prompt PII shielding, tool-call governance, transcript audit, and gateways for MCP tools and Agent-to-Agent traffic.
Security in Depth
WAF content threat detection, OPA authorization, mTLS everywhere, SSRF-safe backend egress policy, anti-smuggling request validation, geo/IP/bot restrictions, and secrets loaded from Vault, AWS, GCP, or Azure.
Resilience & Scale
Six load-balancing algorithms, active and passive health checks, circuit breakers, retries with backoff, service discovery (DNS, Kubernetes, Consul, mesh), multi-CP and multi-DB failover, and graceful shutdown with request draining.
Eight Operating Modes
From a single-node file-based config to a globally distributed Control Plane / Data Plane architecture to a full Kubernetes service mesh — the same binary does it all.
File
YAML/JSON config with SIGHUP hot reload. Perfect for development, single-node, and GitOps deployments.
Database
PostgreSQL, MySQL, SQLite, or MongoDB backed. Full Admin API for dynamic runtime config management.
Control Plane
Centralized config authority. Distributes configuration to Data Planes over secure gRPC streams.
Data Plane
Horizontally scalable traffic processors with multi-CP failover and local config caching for resilience.
Mesh
Service-mesh data plane with six topologies, SPIFFE identity, HBONE, and native or xDS config.
Injector
Kubernetes admission webhook that injects mesh sidecars and traffic-capture init containers.
Node Agent
Per-node eBPF capture manager powering the ambient mesh — no proxy listeners, pure kernel-level plumbing.
Migrate
Runs database schema migrations or config-file upgrades then exits. Built for CI/CD pipelines.
One Endpoint. Eleven AI Providers.
Point your applications at a single OpenAI-compatible endpoint. Ferrum Edge routes each buffered request to OpenAI, Anthropic, Google Gemini/Vertex, Azure OpenAI, AWS Bedrock, Mistral, Cohere, xAI, DeepSeek, Meta Llama, or Hugging Face, normalizes the response, and supports fallback between matching providers. Streaming fallback is limited to selection before a provider is committed; a failure after commitment does not trigger a second provider request.
- Model routing, priority fallback, and per-provider circuit breakers
- Opt-in federation streaming for OpenAI-compatible providers; Anthropic and Gemini normalization through
ai_stream_router - Token budgets per consumer with Redis-coordinated enforcement
- Semantic caching, prompt firewall, PII shield, and output guardrails
- Tool-call governance and configurable transcript audit
- MCP tool gateway and Agent-to-Agent (A2A) gateway for agent traffic
version: "1"
proxies:
- id: ai-api
listen_path: /v1/chat/completions
backend_scheme: https
backend_host: api.openai.com
backend_port: 443
plugins:
- plugin_config_id: ai-gateway
- plugin_config_id: token-budget
plugin_configs:
- id: "ai-gateway"
plugin_name: "ai_federation"
scope: proxy
proxy_id: ai-api
config:
streaming:
enabled: true
providers:
- name: openai
provider_type: openai
api_key: "replace-with-your-openai-api-key"
model_patterns: ["gpt-*"]
- name: anthropic
provider_type: anthropic
api_key: "replace-with-your-anthropic-api-key"
model_patterns: ["claude-*"]
fallback_enabled: true
- id: "token-budget"
plugin_name: "ai_rate_limiter"
scope: proxy
proxy_id: ai-api
config:
limit_by: consumer
token_limit: 500000
window_seconds: 3600
sync_mode: redis
redis_url: "redis://redis:6379/0"
Replace the provider keys and Redis URL before use. File specs do not expand shell environment placeholders. Add an authentication plugin and consumers to enforce budgets by authenticated consumer identity. This example streams OpenAI responses; Anthropic streams require ai_stream_router.
Built to Be Invisible
In the repository’s historical local benchmarks, Ferrum Edge delivered 102,183 RPS on HTTP/1.1 and over 108K on HTTP/2 and raw TCP — and in one historical local Docker run it recorded higher throughput than Envoy, Kong, and Tyk on authenticated API traffic. The goal: your backend is your bottleneck, not your gateway.
- 102,183 RPS on HTTP/1.1 (Apple Silicon, 200 concurrent)
- 108,841 RPS on raw TCP proxy; 103,830 RPS on WebSocket
- Authentication throughput was comparable in that historical workload
- Historical key-auth run: 4% above Envoy, 12% above Kong, 46% above Tyk — not a current-release ranking
- Separate scale harnesses exercise large configurations; results depend on hardware and workload
From Gateway API to Ambient Mesh
Ferrum Edge speaks the standards your cluster already uses — no proprietary CRD lock-in.
Rust-Native. Not Wrapped. Not Ported.
Unlike gateways that bolt scripting layers onto a C or Go core, Ferrum Edge is built in Rust from the ground up. Memory safety without garbage collection. No collector pauses adding jitter to your tail latency. A request path that never stops to wait for a configuration change.
80+ Plugins, Ready to Go
Every capability you need, built in and executed in a deterministic priority pipeline. No marketplace hunting, with documented compatibility and dependency checks.
Meet Ferrum Foundry
The admin panel for your Ferrum Edge gateway. Manage proxies, consumers, plugins, and upstreams through a modern web UI — with periodically refreshed metrics, circuit breaker alerts, and health monitoring built in.
- Full CRUD for proxies, consumers, plugins, and upstreams
- Metrics dashboard with configurable auto-refresh
- Circuit breaker states and connection pool monitoring
- Multi-namespace support for tenant isolation
- Dark and light themes
kind: Consumer
spec:
id: app-mobile
namespace: ferrum
username: app-mobile
credentials:
keyauth:
- key: "${gh-env-secret:alloc=generate}"
# Open a PR → validation, policy review,
# and a change plan per environment.
# Merge → applied to every gateway.
Prefer No UI? Ship Config by Pull Request.
GitForgeOps turns a plain GitHub repository into the control plane for your gateway fleet. Declare proxies, consumers, upstreams, and plugins as YAML — every change is validated, policy-checked, and reviewed in the pull request before it's applied to any environment.
- Multi-environment applies from one repo with per-environment overlays
- Policy-as-code reviews that block bad changes before they merge
- Encrypted credential brokering — no secrets in Git, no Vault required
- Nightly drift detection between declared and live configuration
- Full audit trail in Git; roll back by reverting a commit through the same review and apply pipeline (secret rotation is not undone)
- GitHub-native Actions, Environments, Secrets, and APIs — no external secret manager; plan requirements depend on repository visibility
Publish APIs with Ferrum Nexus
Turn the APIs behind your gateway into a product. Providers publish OpenAPI specs, clients browse the catalog, request access and issue their own credentials — and every gateway change goes through the Nexus backend with role checks and an audit trail.
- OpenAPI catalog with rendered documentation and invoke URLs
- Access requests approved, denied or revoked as gateway ACL grants
- Show-once API keys, basic auth and JWT secrets with rotation
- Client-to-provider messaging, notifications and broadcasts
- White-label branding, audit history and emergency god mode
API Client
v0.1.1 · unsigned preview
Put Your APIs to the Test with Ferrum Anvil
A desktop API client for Windows, macOS and Linux. Build requests, run repeatable tests, inspect performance, and troubleshoot Ferrum Edge with explanations grounded in what actually happened.
- Works with any API; deeper, explicitly bounded diagnostics for declared Ferrum Edge 0.9.8, 0.9.7 and 0.9.5 gateways
- Findings state their confidence and what the evidence does not prove
- HTTP/1.1, HTTP/2, HTTP/3, WebSocket, gRPC, gRPC-Web, SSE, TCP/TLS and UDP/DTLS, plus HBONE mesh tunnels, CONNECT-UDP (MASQUE), PROXY protocol, SPIFFE Workload API identities and opt-in 0-RTT early data
- Load tests in a separate worker process, with a load unit and counts for each protocol: requests, calls, streams, sessions and exchanges
- Runs offline with no account; start without a password (OS keychain) or protect it with a passphrase and recovery key
Ferrum Anvil v0.1.1 is an unsigned preview. Verify downloads with SHA256SUMS. macOS installers are not Developer ID signed or notarized and Windows installers have no code-signing certificate. In-app updates use verified minisign signatures; this does not code-sign the installers. Preview downloads →
Rust Service Toolkit
Pre-release
Build the Services Behind Your Gateway with Ferrum Alloy
A pre-release toolkit for Axum services. Alloy handles configuration, RFC 9457 errors, health, limits, graceful shutdown and request telemetry, and behind Ferrum Edge it shares one verified request story with the gateway.
- Handlers, extractors, routers and Tower middleware stay ordinary Axum
- Trace context trusted only from a verified gateway identity
- Deterministic diagnosis of where a request's time went
- Exports Ferrum Edge file-mode YAML or a GitForgeOps tree
Ready to Try Ferrum Edge?
Download the pre-built binary, or explore the source on GitHub. Free for noncommercial use under the PolyForm Noncommercial license.