FastProxy Use Cases: 5 Production Patterns for Go Microservices

FastProxy is a Go-native, production-grade service proxy that enables secure, high-performance microservice communication through sidecar deployment, internal API gateway patterns, embedded SDK integration, secure data pipelines, and serverless workloads.

FastProxy, developed in the kingson4wu/fast_proxy repository, provides a modular architecture for traffic governance and security in distributed systems. Understanding these FastProxy use cases helps architects select the right deployment pattern for their specific infrastructure requirements, from service mesh sidecars to embedded library integration.

Service Mesh Sidecar Deployment

Deploy FastProxy as a sidecar next to each microservice to terminate encrypted channels, verify signatures, and enforce per-endpoint throttling. This pattern leverages the InProxy component for ingress enforcement and the OutProxy component for egress enforcement.

The sidecar architecture provides secure transport through symmetric and asymmetric encryption, traffic integrity via signature verification and tamper detection, and adaptive flow control through circuit breaking and concurrency guards.

Key implementation files include inproxy/inproxy.go for inbound request termination and outproxy/outproxy.go for outbound traffic management. The outproxy/internal/proxy/proxy.go file implements the core request forwarding logic with encryption, compression, and flow-control capabilities.

// inproxy/example/main.go
package main

import (
	"embed"
	"fmt"
	"github.com/Kingson4Wu/fast_proxy/common/server"
	"github.com/Kingson4Wu/fast_proxy/examples/center"
	"github.com/Kingson4Wu/fast_proxy/inproxy"
	"github.com/Kingson4Wu/fast_proxy/inproxy/inconfig"
	"os"
)

//go:embed *
var ConfigFs embed.FS

func main() {
	cfgBytes, err := ConfigFs.ReadFile("config.yaml")
	if err != nil { fmt.Println(err); os.Exit(1) }
	c := inconfig.LoadYamlConfig(cfgBytes)

	sc := center.GetSC(func() string { return c.ServiceRpcHeaderName() })
	inproxy.NewServer(c, server.WithServiceCenter(sc))
}
// outproxy/example/main.go
package main

import (
	"embed"
	"fmt"
	"github.com/Kingson4Wu/fast_proxy/common/server"
	"github.com/Kingson4Wu/fast_proxy/examples/center"
	"github.com/Kingson4Wu/fast_proxy/outproxy"
	"github.com/Kingson4Wu/fast_proxy/outproxy/outconfig"
	"os"
)

//go:embed *
var ConfigFs embed.FS

func main() {
	cfgBytes, err := ConfigFs.ReadFile("config.yaml")
	if err != nil { fmt.Println(err); os.Exit(1) }
	c := outconfig.LoadYamlConfig(cfgBytes)

	sc := center.GetSC(func() string { return c.ServiceRpcHeaderName() })
	outproxy.NewServer(c, server.WithServiceCenter(sc))
}

East-West API Gateway

Run FastProxy as a dedicated gateway to protect internal APIs and route traffic between clusters. This pattern focuses on payload optimization through compression and comprehensive observability via Zap logging and Prometheus exporters.

The gateway leverages a low-latency stack built on FastHTTP and zero-copy buffers, making it suitable for high-throughput east-west traffic between services. The outproxy/internal/proxy/proxy.go implementation handles request forwarding, encryption, compression, and flow-control policies.

Embedded SDK Integration

Integrate FastProxy directly into a Go service to gain proxy capabilities without a separate process. The core is a library composed of outproxy, inproxy, and common/config packages that can be imported and instantiated programmatically.

Services can import github.com/Kingson4Wu/fast_proxy/outproxy and configure via YAML using common/config/yaml_config.go. The examples/server/server.go file demonstrates how a regular Go service registers itself with the Center and can be wrapped by FastProxy.

// examples/server/server.go
package main

import (
	"fmt"
	"github.com/Kingson4Wu/fast_proxy/common/network"
	"github.com/Kingson4Wu/fast_proxy/examples/center"
	"log"
	"net/http"
	"strconv"
)

func main() {
	mux := http.NewServeMux()
	mux.HandleFunc("/api/service", handler)

	// Register the service with the Center (dynamic config, key rotation, etc.)
	go service(8101, "token_service", mux)

	select {} // keep alive
}

func service(port int, name string, handler http.Handler) {
	srv := &http.Server{
		Addr:    ":" + strconv.Itoa(port),
		Handler: handler,
	}
	ip := network.GetIntranetIp()
	stop := center.RegisterAsync(name, ip, port)

	if err := srv.ListenAndServe(); err != nil {
		close(stop)
		log.Fatal(err)
	}
}

Secure Data Pipeline Protection

Secure high-throughput message streams between services or functions using FastProxy's native protobuf-based transport primitives and hooks for custom codecs. This use case targets data pipelines that require encryption and integrity verification without sacrificing throughput.

The implementation is benchmarked for high concurrency workloads using the benchmark/ suite. The outproxy/internal/proxy/proxy.go implementation can be wrapped around any http.Handler to secure data flows.

Serverless and Function-as-a-Service

Run FastProxy as a lightweight sidecar for functions that need mutual TLS and request throttling. The minimal binary size and Go-only runtime make it suitable for serverless environments with strict resource constraints.

This pattern uses configurable QoS constraints including timeouts and circuit breakers defined in the configuration. The client SDK (client package) works together with inproxy and outproxy to provide lightweight proxy capabilities for functions.

package main

import (
	"context"
	"log"
	"github.com/Kingson4Wu/fast_proxy/client"
)

func main() {
	c, err := client.New(&client.Config{Target: "http://127.0.0.1:8080"})
	if err != nil { log.Fatal(err) }

	resp, err := c.Do(context.Background(), "GET", "/api/service", nil)
	if err != nil { log.Fatal(err) }
	log.Printf("Response: %s", resp)
}

Core Architecture Components

FastProxy implementations rely on four primary components that work together across all use cases:

  • Center (examples/center/*): Stores service metadata, dynamic rule-sets, and key orchestration. Services register themselves via the Center to enable service discovery and dynamic configuration.

  • InProxy (inproxy/inproxy.go): Handles ingress enforcement, terminates inbound TLS, validates request metadata, and performs signature verification.

  • OutProxy (outproxy/outproxy.go): Manages egress enforcement, applies outbound policies, encrypts traffic, and handles compression.

  • Configuration (common/config/yaml_config.go): Provides YAML-based configuration loading used by both InProxy and OutProxy instances.

The common/network/network.go file provides helper functions like GetIntranetIp() used by services to register with the Center using their internal network addresses.

Summary

FastProxy provides a versatile, Go-native solution for securing and governing microservice communication. The five primary FastProxy use cases include:

  • Service mesh sidecars for encrypted, authenticated inter-service communication with circuit breaking
  • East-west API gateways for internal traffic management with compression and observability
  • Embedded SDKs for direct integration into Go applications without separate processes
  • Secure data pipelines for high-throughput protobuf streams with integrity verification
  • Serverless sidecars for lightweight TLS termination and QoS enforcement in function environments

Each pattern leverages FastProxy's modular components—InProxy, OutProxy, and Center—to provide transport security, traffic integrity, and adaptive flow control.

Frequently Asked Questions

What is FastProxy used for?

FastProxy is used to secure and manage network traffic between microservices in Go-based distributed systems. It provides encryption, signature verification, circuit breaking, and service discovery through components like InProxy, OutProxy, and the Center service registry.

How does FastProxy differ from Envoy or Istio?

Unlike Envoy, which is written in C++ and typically deployed as a standalone binary, FastProxy is written entirely in Go and designed to be embedded directly into applications or deployed as lightweight sidecars. It uses FastHTTP for low-latency performance and provides native protobuf support, making it particularly suitable for Go-centric environments where binary size and runtime simplicity matter.

Can FastProxy be embedded directly into existing Go applications?

Yes, FastProxy can be imported as a library using packages like github.com/Kingson4Wu/fast_proxy/outproxy and github.com/Kingson4Wu/fast_proxy/inproxy. The examples/server/server.go file demonstrates how to register services with the Center and wrap existing HTTP handlers with proxy capabilities without deploying separate sidecar processes.

What protocols and data formats does FastProxy support?

FastProxy supports HTTP/HTTPS traffic with built-in TLS termination and mutual TLS authentication. It offers native protobuf-based transport primitives for high-throughput data pipelines and includes hooks for custom codecs. The proxy also provides payload compression and uses FastHTTP for optimized HTTP handling, as seen in the outproxy/internal/proxy/proxy.go implementation.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →