InfraFlow

Sheet IF-01 · Platform overview

Everything between your code and the internet.

Reach machines that sit behind a home router, with a firewall in front of them. Deployments from Git, an edge cache and object storage are on the way. Each resource gets a hostname the moment you create it.

One hostname per resource
Contour interval 40 m

*.production.infraflow.app

Deployments

Connect a GitHub account, pick a repository, and every push is built and switched in with no dropped requests. A version that fails to start changes nothing.

  • Private repositories, a preview address per branch, redeploy on push
  • Roll back to any earlier version in one click, image and variables together
  • Live logs, and every request the service receives
git push
$ git push origin main
build  Dockerfile · 38 s
start  shop, beside the running version
check  answers on port 3000
live  https://shop.production.infraflow.app

*.http · *.tcp · *.udp

Tunnels

An agent on your machine dials out to the edge, so nothing has to be opened on the router. HTTP, raw TCP and UDP all work — game servers and databases included.

  • Outbound-only: works behind NAT, CGNAT and locked-down firewalls
  • QUIC transport, falling back to a WebSocket on port 443 where UDP is blocked
  • Runs as a one-off command or as a service that reconnects on its own
on a machine behind a home router
$ infraflow tunnel http 3000
  https://atlas.http.infraflow.app → localhost:3000
$ infraflow tunnel tcp 5432
  atlas.tcp.infraflow.app:24817 → localhost:5432
$ infraflow tunnel udp 27015
  atlas.udp.infraflow.app:31204 → localhost:27015

every hostname · or your own domain

Web application firewall

Guards everything you run here, and works on its own: point a domain hosted anywhere at the edge and requests are checked on their way to your server.

  • Detects SQL and NoSQL injection, XSS, traversal, command and code injection, SSRF and XXE
  • A policy per site: your own rules, rate limits, and a browser check for automated clients
  • Observe first, then block; every match recorded with the part of the request that tripped it
Firewall events
blockedsqli.semantic
blockedtraversal.path
blockedrate.login
observedscanner.user-agent

*.cdn.infraflow.app

CDN

Point a zone at any site and its responses are cached at the edge, for as long as the site's own caching headers allow.

  • Follows Cache-Control, and serves stale while it revalidates so nobody waits
  • Resizes and converts images on request: ?width=640&format=webp
  • Never stores what is private; purge a zone in one click
a cached response
GET https://assets.cdn.infraflow.app/app.4f9a.js
cache-status: InfraFlow; hit
age:  1284

*.s3.infraflow.app

Object storage

S3-compatible buckets that work with the tools you already use. Keep them private, share with presigned URLs, or make one public and put a CDN zone in front.

  • Works with the AWS CLI, SDKs, rclone and anything else that speaks S3
  • Access keys per bucket, read-write or read-only, and a size quota
  • Each bucket has its own hostname
with the aws cli
$ aws s3 cp backup.tar.zst s3://backups/ \
    --endpoint-url https://s3.infraflow.app
  https://backups.s3.infraflow.app/backup.tar.zst

Profile A–B · One request

The same route for every product.

A request to any InfraFlow hostname crosses the same stages, so the firewall guards a tunnel exactly as it guards a deployment.

  1. Stage 1

    DNS

    The hostname resolves to the nearest edge.

  2. Stage 2

    TLS

    The edge terminates TLS with the zone's certificate.

  3. Stage 3

    WAF

    Rules, rate limits and attack detection run.

  4. Stage 4

    Cache

    For a CDN zone, a stored response is served from here.

  5. Stage 5

    Origin

    Your container, tunnel, bucket or site.

Start here

Create a project. Add the rest when you need it.

An account comes with a workspace. Projects, teammates and API tokens are ready from the first minute.