Overview

The plugin pipeline: IP intelligence, firewall, rate limiting, cache, load balancing, auto-SSL, and logging.

Plugin pipeline

Every request flows through a fixed plugin pipeline. Plugins execute in this exact order and any plugin can short-circuit the remaining pipeline by responding directly.

1. IP Intelligence     (always runs)
2. Firewall            (can short-circuit)
3. Rate Limiting       (can short-circuit)
4. Load Balancer       (can short-circuit — selects upstream target)
5. Cache               (can short-circuit — uses upstream target for revalidation)
6. Logging             (always runs)

Short-circuit behavior

PluginCan short-circuit?When?
IP IntelNoAlways continues
FirewallYesBlock, redirect, or set-header action
Rate LimitYesLimit exceeded → 429
CacheYesCache HIT → serve cached response; REVALIDATING/STALE → serve stale cached data
Load BalancerYesNo healthy upstream → 503

Plugin reference

IP Intelligence

Geo, ASN, VPN, Tor, datacenter, and proxy detection with risk scoring — fully embedded, ~5μs per lookup.

Firewall

Allow, block, redirect, or set headers based on any request attribute.

Rate Limiting

Sliding-window rate limits per IP, header, JWT claim, or composite key.

Cache

Edge caching with TTL, custom keys, SWR/SIE, and singleflight revalidation.

Load Balancer

Round-robin, weighted, least-conn, fast-response, and sticky sessions with health checks.

Auto-SSL

On-demand TLS certificates via Let's Encrypt ACME (HTTP-01).
All plugins share the same condition language — master it once and you can write rules for every plugin.
Copyright © 2026