piko is a free, open source networking & connectivity project written in Go and released under MIT. It has 2,194 GitHub stars, 89 forks and 3 open issues, and was last pushed 11 days ago. On this registry it ranks #40 of 49 tracked projects in Networking & Connectivity, with 5 head-to-head comparisons available.

What is piko?

Piko is an open-source reverse proxy and tunneling server in Go that lets you reach services with no public route by having them open outbound connections, and it is aimed at teams that need to serve production traffic or expose internal services from Kubernetes.

What it is

Piko is a reverse proxy that provides a secure way to connect to services that are not publicly routable, a technique known as tunneling. Rather than the proxy dialing into your services, your upstream services open outbound-only connections (tunnels) to the Piko server, and Piko then forwards incoming traffic back over those established connections. It lives in the HTTP proxying and networking space — its topics are golang, http, http-proxy, reverse-proxy and tunneling — and it is designed to run as a cluster of nodes for fault tolerance, horizontal scaling and zero-downtime deployments, hosted behind an HTTP(S) load balancer on Kubernetes.

The concrete problem it solves is the discoverability requirement of a traditional reverse proxy. In a conventional setup you configure routing rules and the proxy opens connections to your services, which means each upstream must be discoverable and expose a port the proxy can reach. With Piko, upstreams open outbound connections to the server and declare the endpoint they are listening on, so services can run anywhere — a customer network, a bring-your-own-cloud environment, or a user device — without any public route, as long as they can reach the Piko server. It is positioned as an open-source alternative to Ngrok.

Key capabilities

  • Opens HTTP listeners with the agent, for example piko agent http my-endpoint 3000 forwarding to localhost:3000.
  • Proxies TCP traffic with piko agent tcp my-endpoint 3000, or maps a local port with piko forward 3000 my-endpoint.
  • Routes HTTP(S) requests by the Host header, using its first segment as the endpoint ID (for example foo.piko.example.com routed to endpoint foo behind a wildcard domain such as *.piko.example.com), or by the x-piko-endpoint header to avoid wildcard domain setup.
  • Load balances requests across multiple upstreams listening on the same endpoint, with no static endpoint configuration required.
  • Runs as a cluster of nodes for fault tolerance, horizontal scaling and zero-downtime deployments.
  • Provides a Go SDK so an application can listen directly through a standard net.Listener.
  • Piko forward can authenticate with the server and forward connections via TLS.

Who uses it and how

  • Teams exposing services that live in a customer network where no inbound route exists.
  • Operators of bring-your-own-cloud (BYOC) services that need to reach workloads in a customer's environment.
  • Products that must connect to user devices which sit behind NAT or firewalls.
  • Kubernetes administrators hosting Piko behind an HTTP(S) load balancer and scaling it as a node cluster.
  • Developers forwarding a local service to an endpoint, such as sending traffic from port 3000 to endpoint my-endpoint.

Getting started

The README's Getting Started section points to the project Docs and wiki, and the working entry points are the piko agent http my-endpoint 3000 and piko forward 3000 my-endpoint commands against a running Piko server.

How it compares

Piko sits alongside Ngrok, which the README names directly as the service it offers an open-source alternative to, and alongside conventional HTTP reverse proxies that require reachable upstream ports. Its distinguishing position among those tools is that it keeps upstreams outbound-only while still running as a fault-tolerant cluster intended for production traffic rather than ad-hoc development tunnels.

When to use it — and when not

A self-hoster must operate the Piko server itself — as a multi-node cluster behind an HTTP(S) load balancer, typically on Kubernetes — and must also run an agent or Piko forward on the client side, since raw TCP connections cannot address an endpoint directly on the server. Raw TCP additionally requires the local piko forward hop or the Go SDK, which is an extra moving part compared with HTTP, where the endpoint is taken from a header. The project is MIT-licensed Go with active recent activity and three open issues, but the README is a fairly brief overview that defers most operational detail to an external wiki.

project readme (upstream, from github) — read inline


What Is Piko?

Piko is a reverse proxy that provides a secure way to connect to services that aren’t publicly routable, known as tunneling. Instead of sending traffic directly to your services, your upstream services open outbound-only connections (tunnels) to Piko, then Piko forwards traffic to your services via their established connections.

Piko has two key design goals:

  • Built to serve production traffic by running as a cluster of nodes for fault tolerance, horizontal scaling and zero-downtime deployments
  • Simple to host behind a HTTP(S) load balancer on Kubernetes

Therefore Piko can be used as an open-source alternative to Ngrok.

Such as you may use Piko to expose services in a customer network, a bring your own cloud (BYOC) service, or to connect to user devices.

Reverse Proxy

In a traditional reverse proxy, you configure routing rules describing how to route incoming traffic to your upstream services. The proxy will then open connections to your services and forward incoming traffic. This means your upstream services must be discoverable and have an exposed port that's accessible from the proxy.

Whereas with Piko, your upstreams open outbound-only connections to the Piko server and specify what endpoint they are listening on. Piko then forwards incoming traffic to the correct upstream via its outbound connection.

Therefore your services may run anywhere without requiring a public route, as long as they can open a connection to the Piko server.

Endpoints

Upstream services listen for traffic on a particular endpoint. Piko then manages routing incoming connections and requests to an upstream service listening on the target endpoint. If multiple upstreams are listening on the same endpoint, requests are load balanced among the available upstreams.

No static configuration is required to configure endpoints, upstreams can listen on any endpoint they choose.

You can open an upstream listener using the Piko agent, which supports both HTTP and TCP upstreams. Such as to listen on endpoint my-endpoint and forward traffic to localhost:3000:

# HTTP listener.
$ piko agent http my-endpoint 3000

# TCP listener.
$ piko agent tcp my-endpoint 3000

You can also use the Go SDK to listen directly from your application using a standard net.Listener.

HTTP(S)

Piko acts as a transparent HTTP(S) reverse proxy.

Incoming HTTP(S) requests identify the target endpoint to connect to using either the Host header or x-piko-endpoint header.

When using the Host header, Piko uses the first segment as the endpoint ID. Such as if your hosting Piko with a wildcard domain at *.piko.example.com, sending a request to foo.piko.example.com will be routed to an upstream listening on endpoint foo.

To avoid having to set up a wildcard domain you can instead use the x-piko-endpoint header, such as if Piko is hosted at piko.example.com, you can send requests to endpoint foo using header x-piko-endpoint: foo.

TCP

Piko supports proxying TCP traffic, though unlike HTTP it requires using either Piko forward or the Go SDK to map the desired local TCP port to the target endpoint.

Piko forward listens on a local TCP port and forwards connections to the configured upstream endpoint via the Piko server.

Such as to listen on port 3000 and forward connections to endpoint my-endpoint:

piko forward 3000 my-endpoint

Note unlike with HTTP, there is no way to identify the target endpoint when connecting with raw TCP, which is why you must first connect to Piko forward instead of connecting directly to the Piko server. Piko forward can also authenticate with the server and forward connections via TLS.

You can also use the Go SDK to open a net.Conn that's connected to the configured endpoint.

Design Goals

Production Traffic

Piko is built to serve production traffic by running the Piko server as a cluster of nodes to be fault tolerant, scale horizontally and support zero downtime deployments.

Say an upstream is listening for traffic on endpoint E and connects to node N. Node N will notify the other nodes that it has a listener for endpoint E, so they can route incoming traffic for that endpoint to node N, which then forwards the traffic to the upstream via its outbound-only connection to the server. If node N fails or is deprovisioned, the upstream listener will reconnect to another node and the cluster propagates the new routing information to the other nodes in the cluster. See How Piko Works for details.

Piko also has a Prometheus endpoint, access logging, and status API so you can monitor your deployment and debug issues. See observability for details.

Hosting

Piko is built to be simple to host on Kubernetes. This means it can run as a cluster of nodes (such as a StatefulSet), supports gradual rollouts, and can be hosted behind a HTTP load balancer or Kubernetes Gateway.

Upstream services and downstream clients may connect to any node in the cluster via the load balancer, then the cluster manages routing traffic to the appropriate upstream.

See Kubernetes for details.

Getting Started

See Getting Started.

How Piko Works

See How Piko Works.

Support

Use GitHub Discussions to ask questions, get help, or suggest ideas.

Docs

See Wiki.

Contributing

See CONTRIBUTING.

License

MIT License, please see LICENSE for details.

Frequently asked questions

Is piko free to use?

piko is open source under the MIT licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does piko do?

An open-source alternative to Ngrok, designed to serve production traffic and be simple to host (particularly on Kubernetes)

What is piko written in?

piko is primarily written in Go. Its source is publicly available at https://github.com/andydunstall/piko, and it has 2,194 GitHub stars.