Zum Hauptinhalt wechseln
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.bfe-d46907a5-0ad7-4635-8d58-af0bfa0aac91/image4_logolarge.png

BFE on Ubuntu 24.04

durch cloudimg

Open source layer 7 load balancer on Ubuntu 24.04, routing by host, path, header or cookie

BFE (originally Baidu Front End) is an open source layer 7 load balancer and reverse proxy, and a Cloud Native Computing Foundation sandbox project. It sits at the edge of your estate, terminates client traffic and forwards it to the right backend. Routing decisions are made on the content of the request rather than just the port it arrived on: host, path, header, cookie, query string and client address are all first class matching conditions, expressed in a small condition language. Matched traffic is balanced across named clusters and sub clusters with health checking, weighting and configurable retries, so an unhealthy backend drops out of rotation without you touching anything.

BFE speaks HTTP, HTTPS, HTTP/2, WebSocket, gRPC and FastCGI, carries a modular plugin framework for rewriting, redirecting, blocking, tagging and rate limiting traffic, and exposes rich built in counters so you can see exactly what your edge is doing. This cloudimg image ships the official upstream release binary on Ubuntu 24.04 LTS, fetched from the project's own release and pinned by SHA-256, with the exact artifact and its digest recorded on the VM. BFE runs under systemd as an unprivileged account.

This is a load balancer that is actually load balancing the moment it boots, not an empty daemon waiting to be configured. Because a fresh VM has no backends yet, the image ships one: a tiny demo backend bound to the loopback interface that the default configuration routes every request to. On first boot a real request travels through BFE end to end and returns the backend's page. That backend is reachable only over loopback, so a response carrying its marker can only have arrived by being proxied, and BFE stamps its own header onto the way out, making both ends of the journey visible in a single request. A shipped self test command proves the whole path in one line. You then repoint BFE at your own servers by editing one file and reloading.

Secure by default. BFE has no console, no account and no password, so there is no default login to leak. The upstream release ships sample credentials and keys, two seeded HTTP basic accounts, a signing key, a session ticket key and four private keys, and every one of them is removed at build time with the build failing closed if any survives. The TLS certificate and session ticket key are generated on your VM at first boot, so the image contains no key material and no two instances ever share any. The metrics port is confined to the loopback interface in the kernel, because it also serves an unauthenticated configuration reload endpoint. The cipher suite list drops RC4 and 3DES, legacy SSLv2 ClientHello support is off, and the WebAssembly plugin and AI gateway modules are not loaded.

BFE is licensed under Apache-2.0, free and open source with no per user or per deployment fee, and is redistributed unmodified with its licence text retained on the image. cloudimg provides the packaging, the hardened configuration, the systemd integration, the working demonstration backend, the per instance TLS bootstrap, the self test tooling, security patching and 24/7 support with a guaranteed 24 hour response SLA. BFE is an independent open source project and this image is not affiliated with or endorsed by the BFE project, the CNCF or Baidu.

Auf einen Blick

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.bfe-d46907a5-0ad7-4635-8d58-af0bfa0aac91/image0_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.bfe-d46907a5-0ad7-4635-8d58-af0bfa0aac91/image3_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.bfe-d46907a5-0ad7-4635-8d58-af0bfa0aac91/image1_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.bfe-d46907a5-0ad7-4635-8d58-af0bfa0aac91/image2_screenshot04.png
Deutsch (Luxemburg)
Abwahlsymbol „Ihre Datenschutzoptionen“ Ihre Datenschutzoptionen
Verbraucherdatenschutz für Gesundheitsdaten Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies