Overview
The plugin pipeline: IP intelligence, firewall, rate limiting, cache, load balancing, auto-SSL, and logging.
Plugin pipeline
Every request flows through a fixed plugin pipeline. Plugins execute in this exact order and any plugin can short-circuit the remaining pipeline by responding directly.
1. IP Intelligence (always runs)
2. Firewall (can short-circuit)
3. Rate Limiting (can short-circuit)
4. Load Balancer (can short-circuit — selects upstream target)
5. Cache (can short-circuit — uses upstream target for revalidation)
6. Logging (always runs)
Short-circuit behavior
| Plugin | Can short-circuit? | When? |
|---|---|---|
| IP Intel | No | Always continues |
| Firewall | Yes | Block, redirect, or set-header action |
| Rate Limit | Yes | Limit exceeded → 429 |
| Cache | Yes | Cache HIT → serve cached response; REVALIDATING/STALE → serve stale cached data |
| Load Balancer | Yes | No healthy upstream → 503 |
Plugin reference
IP Intelligence
Geo, ASN, VPN, Tor, datacenter, and proxy detection with risk scoring — fully embedded, ~5μs per lookup.
All plugins share the same condition language — master it once and you can write rules for every plugin.