The fastest programmable gateway for services, models and tools.
Arion Proxy is a high-performance, memory-safe proxy written in Rust. It natively supports the Envoy configuration model and the commonly used Envoy features, and extends them with Arion-native capabilities for AI workloads.
- Memory safe. Implemented in Rust, avoiding entire classes of memory-management and data-race bugs and making Arion a robust and secure foundation for your traffic.
- Envoy-native configuration. Arion's configuration is generated from Envoy's xDS protobuf definitions and is consumed the same way Envoy consumes it — as static bootstrap config or dynamically from an existing xDS control plane. The commonly used Envoy features are supported: routing, load balancing, TLS, JWT authentication, global rate limiting, circuit breaking, connection limits, external processing, health checks, and more — see the example configurations in arion-proxy/conf/.
- Native AI extensions. Alongside Envoy feature parity, Arion adds its own extensions for AI traffic, such as an MCP gateway with RBAC for routing model and tool traffic.
- Programmable. HTTP filters can be written in WebAssembly and loaded at runtime. The Wasm SDK lives in this repo (arion-wasm-sdk).
- Observable. Prometheus metrics, distributed tracing, and access logging.
git clone https://github.com/arion-gateway/arion
cd arion
git submodule update --init --force
cargo buildcargo run --bin arion -- --config arion-proxy/conf/arion-runtime.yamlarion-proxy/conf/ contains further example configurations (JWT, rate limiting, circuit breaking, health checks, and more).
# Build
docker build -t arion-proxy -f docker/Dockerfile .
# Run
docker run -p 8000:8000 --name arion-proxy arion-proxy
# Verify
curl -v http://localhost:8000/direct-response # HTTP 200 with "meow! 🐱"See docker/README.md for detailed Docker options, including testing load balancing against real backends.
Optional features of the arion-proxy crate (enable with
--features <name>):
| Feature | Description |
|---|---|
wasm |
HTTP Wasm filter host (Wasmtime). Required to load Wasm HTTP filters at runtime. |
metrics |
Metrics collection |
prometheus |
Prometheus metrics export (implies metrics) |
access-log |
Access logging |
tracing |
Distributed tracing |
config-dump |
Admin config dump support |
jemalloc |
Use jemalloc as the allocator |
instrumentation |
Internal instrumentation |
dhat-heap |
Heap profiling with dhat |
Example:
cargo build -p arion-proxy --features wasmTo control how many CPU cores/threads Arion uses, set the ARION_CPU_LIMIT
environment variable. This is especially useful in containerized
environments where access to /sys/fs is restricted; Arion uses the value
to size its worker thread pool.
See docs/ for guides, including metrics, tracing, access logging, global rate limiting, the MCP gateway, and demos.
Arion Proxy is licensed under the Apache License, Version 2.0.