Ferrum Edge Logo

API Gateway. AI Gateway.
Service Mesh.
One Rust-Powered Binary.

Every protocol. 80+ built-in plugins. Eight operating modes.

Ferrum Edge is a high-performance edge platform engineered in Rust. Route, secure, and observe HTTP, gRPC, WebSocket, TCP, and UDP traffic — govern LLM and agent traffic across 11 AI providers — and run a SPIFFE-identity service mesh, all from a single gateway binary.

HTTP/1.1 HTTP/2 HTTP/3 QUIC WebSocket gRPC SSE TCP UDP TLS/DTLS MCP A2A
102K+
Historical HTTP/1.1 RPS
80+
Built-in plugins
8
Operating modes
11
AI providers, one API

Three Products in One Binary

Most teams run separate software for API management, AI traffic governance, and service-to-service networking. Ferrum Edge consolidates all three — same binary, same configuration model, same plugins.

🌐

API Gateway

Dynamic routing, 10+ authentication methods, rate limiting, WAF threat detection, transformation, caching, and full-stack observability for HTTP/1.1 through HTTP/3, gRPC, WebSocket, TCP, and UDP — with zero-downtime configuration reloads.

🤖

AI Gateway

One OpenAI-compatible endpoint routing buffered requests to 11 providers. Streaming is opt-in for supported providers; fallback stops once a streaming provider is committed. Token budgets, semantic caching, prompt firewalls, PII redaction, tool-call governance, compliance transcripts — plus dedicated MCP and Agent-to-Agent gateways for agent traffic.

🛡

Service Mesh

Six mesh topologies — sidecar, ambient, waypoints, east-west, and egress gateways — with SPIFFE identity, mutual TLS, HBONE, transparent DNS, mesh authorization policy, and Istio/Gateway API compatibility on Kubernetes.

Up and Running in Minutes

Edge remains pre-1.0. Pin an explicit version tag like v0.9.10 for reproducible installs — see releases for upgrade notes and companion-tool compatibility.

bash
# Download, verify, and install v0.9.10 for Linux x86_64 (glibc 2.34+).
# Other platforms: use the matching block in the install guides.
ASSET=ferrum-edge-linux-x86_64
BASE=https://github.com/ferrum-edge/ferrum-edge/releases/download/v0.9.10
curl -fsSLO "$BASE/$ASSET" &&
curl -fsSLO "$BASE/$ASSET.sha256" &&
sha256sum -c "$ASSET.sha256" &&
sudo install -m 0755 "$ASSET" /usr/local/bin/ferrum-edge &&
/usr/local/bin/ferrum-edge version

# Create a minimal config that proxies /api to a backend on localhost:3000
cat > config.yaml << 'EOF'
version: "1"
proxies:
  - id: "my-api"
    listen_path: "/api"
    backend_scheme: http
    backend_host: "localhost"
    backend_port: 3000
    strip_listen_path: true
plugin_configs: []
EOF

# Validate, then start Ferrum Edge in the foreground (file mode is inferred from --spec)
ferrum-edge validate --spec config.yaml &&
ferrum-edge run --spec config.yaml -v

A failed download or checksum stops the chain before anything is installed. The gateway keeps running in the foreground, and the sample route expects a backend on localhost:3000; the Linux and macOS guides continue from here with a throwaway test backend, a liveness check, and a real proxied request from a second terminal.

Everything You Need at the Edge

Ferrum Edge is engineered from the ground up for speed and reliability — no garbage-collector pauses, no lock contention on configuration reads, no compromises.

⚡

Lock-Free Configuration Reads

Requests never wait in line to read configuration. Config updates are atomic swaps — in-flight requests finish on the old config while new requests instantly see the new one. Zero downtime, zero stalls.

🔌

80+ Built-in Plugins

Authentication, authorization, OPA policy, WAF, rate limiting, adaptive concurrency, AI/LLM governance, transformation, chaos testing, chargeback, and observability — all first-class, all priority-ordered, no marketplace required.

🌐

True Multi-Protocol

HTTP/1.1 through HTTP/3 QUIC, WebSocket over all three HTTP versions, gRPC and gRPC-Web, SSE streaming, raw TCP and UDP with TLS/DTLS termination, origination, or passthrough. One gateway, every protocol.

🤖

Full AI Traffic Governance

14 AI-focused plugins: provider federation with streaming, token-aware rate limiting, semantic firewall and cache, prompt PII shielding, tool-call governance, transcript audit, and gateways for MCP tools and Agent-to-Agent traffic.

🛡

Security in Depth

WAF content threat detection, OPA authorization, mTLS everywhere, SSRF-safe backend egress policy, anti-smuggling request validation, geo/IP/bot restrictions, and secrets loaded from Vault, AWS, GCP, or Azure.

📈

Resilience & Scale

Six load-balancing algorithms, active and passive health checks, circuit breakers, retries with backoff, service discovery (DNS, Kubernetes, Consul, mesh), multi-CP and multi-DB failover, and graceful shutdown with request draining.

Eight Operating Modes

From a single-node file-based config to a globally distributed Control Plane / Data Plane architecture to a full Kubernetes service mesh — the same binary does it all.

📄

File

YAML/JSON config with SIGHUP hot reload. Perfect for development, single-node, and GitOps deployments.

🗃

Database

PostgreSQL, MySQL, SQLite, or MongoDB backed. Full Admin API for dynamic runtime config management.

🏛

Control Plane

Centralized config authority. Distributes configuration to Data Planes over secure gRPC streams.

⚡

Data Plane

Horizontally scalable traffic processors with multi-CP failover and local config caching for resilience.

🛡

Mesh

Service-mesh data plane with six topologies, SPIFFE identity, HBONE, and native or xDS config.

💉

Injector

Kubernetes admission webhook that injects mesh sidecars and traffic-capture init containers.

📡

Node Agent

Per-node eBPF capture manager powering the ambient mesh — no proxy listeners, pure kernel-level plumbing.

🔧

Migrate

Runs database schema migrations or config-file upgrades then exits. Built for CI/CD pipelines.

Guide: Running Every Mode →

One Endpoint. Eleven AI Providers.

Point your applications at a single OpenAI-compatible endpoint. Ferrum Edge routes each buffered request to OpenAI, Anthropic, Google Gemini/Vertex, Azure OpenAI, AWS Bedrock, Mistral, Cohere, xAI, DeepSeek, Meta Llama, or Hugging Face, normalizes the response, and supports fallback between matching providers. Streaming fallback is limited to selection before a provider is committed; a failure after commitment does not trigger a second provider request.

  • Model routing, priority fallback, and per-provider circuit breakers
  • Opt-in federation streaming for OpenAI-compatible providers; Anthropic and Gemini normalization through ai_stream_router
  • Token budgets per consumer with Redis-coordinated enforcement
  • Semantic caching, prompt firewall, PII shield, and output guardrails
  • Tool-call governance and configurable transcript audit
  • MCP tool gateway and Agent-to-Agent (A2A) gateway for agent traffic
yaml — AI routing and token budgets
version: "1"
proxies:
  - id: ai-api
    listen_path: /v1/chat/completions
    backend_scheme: https
    backend_host: api.openai.com
    backend_port: 443
    plugins:
      - plugin_config_id: ai-gateway
      - plugin_config_id: token-budget
plugin_configs:
  - id: "ai-gateway"
    plugin_name: "ai_federation"
    scope: proxy
    proxy_id: ai-api
    config:
      streaming:
        enabled: true
      providers:
        - name: openai
          provider_type: openai
          api_key: "replace-with-your-openai-api-key"
          model_patterns: ["gpt-*"]
        - name: anthropic
          provider_type: anthropic
          api_key: "replace-with-your-anthropic-api-key"
          model_patterns: ["claude-*"]
      fallback_enabled: true
  - id: "token-budget"
    plugin_name: "ai_rate_limiter"
    scope: proxy
    proxy_id: ai-api
    config:
      limit_by: consumer
      token_limit: 500000
      window_seconds: 3600
      sync_mode: redis
      redis_url: "redis://redis:6379/0"

Replace the provider keys and Redis URL before use. File specs do not expand shell environment placeholders. Add an authentication plugin and consumers to enforce budgets by authenticated consumer identity. This example streams OpenAI responses; Anthropic streams require ai_stream_router.

Built to Be Invisible

In the repository’s historical local benchmarks, Ferrum Edge delivered 102,183 RPS on HTTP/1.1 and over 108K on HTTP/2 and raw TCP — and in one historical local Docker run it recorded higher throughput than Envoy, Kong, and Tyk on authenticated API traffic. The goal: your backend is your bottleneck, not your gateway.

  • 102,183 RPS on HTTP/1.1 (Apple Silicon, 200 concurrent)
  • 108,841 RPS on raw TCP proxy; 103,830 RPS on WebSocket
  • Authentication throughput was comparable in that historical workload
  • Historical key-auth run: 4% above Envoy, 12% above Kong, 46% above Tyk — not a current-release ranking
  • Separate scale harnesses exercise large configurations; results depend on hardware and workload
RPS by Protocol
TCP Proxy
108K
HTTP/2
108K
WebSocket
103K
HTTP/1.1
102K
HTTP/1.1+TLS
101K
UDP
82K
gRPC
68K
HTTP/3 QUIC
53K

From Gateway API to Ambient Mesh

Ferrum Edge speaks the standards your cluster already uses — no proprietary CRD lock-in.

⎈ Gateway API
HTTPRoute, GRPCRoute, and UDPRoute translation with weighted traffic splits and conformance-tested behavior
🛡 Istio Compatible
VirtualService route splits, AuthorizationPolicy, RequestAuthentication, PeerAuthentication, and Telemetry API
🔑 SPIFFE Identity
Workload identity from mTLS certificates, SPIRE integration or built-in Workload API, trust-domain federation
🌐 Multi-Cluster
East-west gateways with SNI passthrough, cross-cluster identity validation, and trust bundle federation
Kubernetes Deployment Guide →

Rust-Native. Not Wrapped. Not Ported.

Unlike gateways that bolt scripting layers onto a C or Go core, Ferrum Edge is built in Rust from the ground up. Memory safety without garbage collection. No collector pauses adding jitter to your tail latency. A request path that never stops to wait for a configuration change.

🦊
Memory Safe
Rust helps prevent memory-safety bugs; native dependencies and runtime behavior still need testing.
⚡
No GC Pauses
No garbage collector means no stop-the-world pauses. Latency under saturation still depends on CPU headroom, plugins, and your upstreams.
🔒
Never Waits in Line
Requests read config without locks, so config changes never stall traffic.
See Why Teams Choose Ferrum Edge →

80+ Plugins, Ready to Go

Every capability you need, built in and executed in a deterministic priority pipeline. No marketplace hunting, with documented compatibility and dependency checks.

🔐 Authentication
mTLS, OAuth2, OIDC, JWT, JWKS + DPoP, API Key, LDAP, Basic, HMAC, SOAP WS-Security
🛡 Security & Policy
WAF, OPA, ACL, geo/IP/bot restriction, CORS, security headers, body & OpenAPI validation
🤖 AI / LLM / Agents
Federation, streaming router, semantic firewall & cache, token budgets, tool governor, MCP & A2A gateways
📊 Observability
OpenTelemetry, Prometheus, Loki, Kafka, StatsD, proxy alerts, chargeback, custom log schemas
Browse the Full Plugin Catalog →
v0.4.0 · early access

Meet Ferrum Foundry

The admin panel for your Ferrum Edge gateway. Manage proxies, consumers, plugins, and upstreams through a modern web UI — with periodically refreshed metrics, circuit breaker alerts, and health monitoring built in.

  • Full CRUD for proxies, consumers, plugins, and upstreams
  • Metrics dashboard with configurable auto-refresh
  • Circuit breaker states and connection pool monitoring
  • Multi-namespace support for tenant isolation
  • Dark and light themes
Ferrum Foundry Dashboard
yaml — consumer with brokered credentials
kind: Consumer
spec:
  id: app-mobile
  namespace: ferrum
  username: app-mobile
  credentials:
    keyauth:
      - key: "${gh-env-secret:alloc=generate}"

# Open a PR → validation, policy review,
# and a change plan per environment.
# Merge → applied to every gateway.
Active buildout · pre-launch

Prefer No UI? Ship Config by Pull Request.

GitForgeOps turns a plain GitHub repository into the control plane for your gateway fleet. Declare proxies, consumers, upstreams, and plugins as YAML — every change is validated, policy-checked, and reviewed in the pull request before it's applied to any environment.

  • Multi-environment applies from one repo with per-environment overlays
  • Policy-as-code reviews that block bad changes before they merge
  • Encrypted credential brokering — no secrets in Git, no Vault required
  • Nightly drift detection between declared and live configuration
  • Full audit trail in Git; roll back by reverting a commit through the same review and apply pipeline (secret rotation is not undone)
  • GitHub-native Actions, Environments, Secrets, and APIs — no external secret manager; plan requirements depend on repository visibility
v0.3.0 · Edge v0.9.9

Publish APIs with Ferrum Nexus

Turn the APIs behind your gateway into a product. Providers publish OpenAPI specs, clients browse the catalog, request access and issue their own credentials — and every gateway change goes through the Nexus backend with role checks and an audit trail.

  • OpenAPI catalog with rendered documentation and invoke URLs
  • Access requests approved, denied or revoked as gateway ACL grants
  • Show-once API keys, basic auth and JWT secrets with rotation
  • Client-to-provider messaging, notifications and broadcasts
  • White-label branding, audit history and emergency god mode
Ferrum Nexus API catalog
Ferrum Anvil diagnosing an HTTP 502 from a Ferrum Edge gateway. The finding Gateway could not prepare a connection to the backend is marked Likely, scoped to the gateway-to-backend leg and owned by the gateway operator, with a list of what it does not prove, such as that TLS or DNS failed.
Pre-release build. Captured by the automated desktop test suite against a local Ferrum Edge 0.9.7 gateway.
Ferrum Anvil logo v0.1.1 · unsigned preview

Put Your APIs to the Test with Ferrum Anvil

A desktop API client for Windows, macOS and Linux. Build requests, run repeatable tests, inspect performance, and troubleshoot Ferrum Edge with explanations grounded in what actually happened.

  • Works with any API; deeper, explicitly bounded diagnostics for declared Ferrum Edge 0.9.8, 0.9.7 and 0.9.5 gateways
  • Findings state their confidence and what the evidence does not prove
  • HTTP/1.1, HTTP/2, HTTP/3, WebSocket, gRPC, gRPC-Web, SSE, TCP/TLS and UDP/DTLS, plus HBONE mesh tunnels, CONNECT-UDP (MASQUE), PROXY protocol, SPIFFE Workload API identities and opt-in 0-RTT early data
  • Load tests in a separate worker process, with a load unit and counts for each protocol: requests, calls, streams, sessions and exchanges
  • Runs offline with no account; start without a password (OS keychain) or protect it with a passphrase and recovery key

Ferrum Anvil v0.1.1 is an unsigned preview. Verify downloads with SHA256SUMS. macOS installers are not Developer ID signed or notarized and Windows installers have no code-signing certificate. In-app updates use verified minisign signatures; this does not code-sign the installers. Preview downloads →

Ferrum Alloy logo Pre-release

Build the Services Behind Your Gateway with Ferrum Alloy

A pre-release toolkit for Axum services. Alloy handles configuration, RFC 9457 errors, health, limits, graceful shutdown and request telemetry, and behind Ferrum Edge it shares one verified request story with the gateway.

  • Handlers, extractors, routers and Tower middleware stay ordinary Axum
  • Trace context trusted only from a verified gateway identity
  • Deterministic diagnosis of where a request's time went
  • Exports Ferrum Edge file-mode YAML or a GitForgeOps tree

Ready to Try Ferrum Edge?

Download the pre-built binary, or explore the source on GitHub. Free for noncommercial use under the PolyForm Noncommercial license.

Download Latest Installation Guide View Licensing