Introduction
What Quayel Gateway is, how it works, and where to start.
Introduction
Quayel Gateway is a high-performance API gateway built on Pingora — the Rust framework behind Cloudflare's edge. It provides embedded IP intelligence, firewall, rate limiting, edge caching, load balancing, and on-demand TLS, all configured through a single JSON file.
{
"gateway_id": "gw-prod-01",
"gateway_name": "production",
"server_name": "api.example.com",
"config_version": "2026-01-01-001",
"listen": { "http": "0.0.0.0:8080" },
"plugins": {
"ip_intel": { "enabled": true },
"load_balancer": { "enabled": true, "load_balancers": [ /* ... */ ] },
"logging": { "enabled": true, "mode": "file", "file": { "path": "/var/log/quayel/access.jsonl" } }
}
}
One JSON config file, one binary, zero external dependencies.
What makes Quayel different
Zero external dependencies
All IP intelligence data (~140 MB of MMDB + CIDR lists) is compiled directly into the binary. No Redis, no external databases, no downloads on startup.
Single binary deployment
Copy one file, write one JSON config, start serving. ~29 MB runtime RSS.
On-demand TLS
Automatic certificate provisioning via Let's Encrypt ACME. Certs are obtained on first request, not on startup. All state in memory for O(1) lookups.
Embedded IP intelligence
Every request is enriched with country, ASN, VPN/Tor/datacenter/proxy detection, risk scoring, and network classification — all in ~5μs (cached).
Deterministic plugin pipeline
Plugins execute in a fixed order: IP Intel → Firewall → Rate Limit → Load Balancer → Cache → Logging. Any plugin can short-circuit the pipeline.
Structured JSONL logging
Every request produces a single JSON line with full context: IP intel, firewall decisions, rate limit state, cache status, load balancer target, and per-phase timing.
How a request flows
Request In
│
▼
IP Intelligence ──→ Firewall ──→ Rate Limit ──→ Load Balancer ──→ Cache ──→ Upstream
│ │ │ │ │
│ enrich: │ allow/ │ throttle/ │ select │ HIT → respond
│ country, ASN, │ block/ │ 429 │ upstream │ MISS → fetch
│ VPN, Tor, risk │ redirect │ │ target │ REVALIDATING
│ │ │ │ │ → serve stale
▼ ▼ ▼ ▼ ▼
Logging (JSONL access log, one line per request)
Any plugin can return a response and short-circuit the remaining pipeline. Rules inside a plugin run in array order — first match wins.
Where to go next
Building configs with an AI agent? Install the Quayel Gateway skill or point the agent at the AI Agent Guide — a machine-oriented contract with the exact schema, enums, defaults, and a validation loop.
Deep dives
Full reference material lives alongside these docs:
| Page | What it covers |
|---|---|
| Architecture | System design, request context, embedded data, concurrency model |
| Configuration | Every config.json field, with a complete example |
| Conditions | The matching language shared by firewall, rate limit, cache, and LB rules |
| Data Sources | Embedded datasets, sources, licenses, and the update process |
| Logging | JSONL access-log format and every field |
| Testing & Validation | The all-rules config and 57-assertion live test suite |
| API Reference | Upstream headers, response bodies, and variables |
| Versioning | Releases, config_version, dataset vintages, and docs versions |