Introduction

What Quayel Gateway is, how it works, and where to start.

Introduction

Quayel Gateway is a high-performance API gateway built on Pingora — the Rust framework behind Cloudflare's edge. It provides embedded IP intelligence, firewall, rate limiting, edge caching, load balancing, and on-demand TLS, all configured through a single JSON file.

{
  "gateway_id": "gw-prod-01",
  "gateway_name": "production",
  "server_name": "api.example.com",
  "config_version": "2026-01-01-001",
  "listen": { "http": "0.0.0.0:8080" },
  "plugins": {
    "ip_intel": { "enabled": true },
    "load_balancer": { "enabled": true, "load_balancers": [ /* ... */ ] },
    "logging": { "enabled": true, "mode": "file", "file": { "path": "/var/log/quayel/access.jsonl" } }
  }
}

One JSON config file, one binary, zero external dependencies.

What makes Quayel different

Zero external dependencies

All IP intelligence data (~140 MB of MMDB + CIDR lists) is compiled directly into the binary. No Redis, no external databases, no downloads on startup.

Single binary deployment

Copy one file, write one JSON config, start serving. ~29 MB runtime RSS.

On-demand TLS

Automatic certificate provisioning via Let's Encrypt ACME. Certs are obtained on first request, not on startup. All state in memory for O(1) lookups.

Embedded IP intelligence

Every request is enriched with country, ASN, VPN/Tor/datacenter/proxy detection, risk scoring, and network classification — all in ~5μs (cached).

Deterministic plugin pipeline

Plugins execute in a fixed order: IP Intel → Firewall → Rate Limit → Load Balancer → Cache → Logging. Any plugin can short-circuit the pipeline.

Structured JSONL logging

Every request produces a single JSON line with full context: IP intel, firewall decisions, rate limit state, cache status, load balancer target, and per-phase timing.

How a request flows

Request In
   │
   ▼
IP Intelligence ──→ Firewall ──→ Rate Limit ──→ Load Balancer ──→ Cache ──→ Upstream
   │                  │             │                │              │
   │  enrich:         │  allow/     │  throttle/     │  select      │  HIT → respond
   │  country, ASN,   │  block/     │  429           │  upstream    │  MISS → fetch
   │  VPN, Tor, risk  │  redirect   │                │  target      │  REVALIDATING
   │                  │             │                │              │  → serve stale
   ▼                  ▼             ▼                ▼              ▼
                    Logging (JSONL access log, one line per request)

Any plugin can return a response and short-circuit the remaining pipeline. Rules inside a plugin run in array order — first match wins.

Where to go next

Installation

Run Quayel Gateway with Docker in minutes. APT and direct downloads coming soon.

Project Structure

How the repository is organized and where the gateway keeps its files at runtime.

Plugins

IP intelligence, firewall, rate limiting, cache, load balancing, and auto-SSL.

AI

Configure the gateway with an AI agent: skill package, installation, and the full agent guide.
Building configs with an AI agent? Install the Quayel Gateway skill or point the agent at the AI Agent Guide — a machine-oriented contract with the exact schema, enums, defaults, and a validation loop.

Deep dives

Full reference material lives alongside these docs:

PageWhat it covers
ArchitectureSystem design, request context, embedded data, concurrency model
ConfigurationEvery config.json field, with a complete example
ConditionsThe matching language shared by firewall, rate limit, cache, and LB rules
Data SourcesEmbedded datasets, sources, licenses, and the update process
LoggingJSONL access-log format and every field
Testing & ValidationThe all-rules config and 57-assertion live test suite
API ReferenceUpstream headers, response bodies, and variables
VersioningReleases, config_version, dataset vintages, and docs versions
Copyright © 2026