trickster is a free, open source networking & connectivity project written in Go and released under Apache-2.0. It has 2,092 GitHub stars, 190 forks and 6 open issues, and was last pushed 30 hours ago. On this registry it ranks #41 of 55 tracked projects in Networking & Connectivity, with 5 head-to-head comparisons available.

What is trickster?

Trickster is an open-source Go HTTP reverse proxy cache and time series database query accelerator for operators who want faster dashboards and a hardened edge in front of HTTP services.

What it is

Trickster is a reverse proxy cache written in Go, licensed under Apache-2.0, and hosted by the Cloud Native Computing Foundation as a sandbox-level project. It sits between clients and backends, caching HTTP responses and eliminating redundant computations against the time series databases it fronts, which dramatically improves dashboard chart rendering times for end users. It works with virtually any dashboard application querying supported TSDBs, including Prometheus, ClickHouse, InfluxDB, VictoriaMetrics, Apache Druid, Graphite, and GreptimeDB.

The concrete problem it solves is that read-heavy dashboard and TSDB environments, as well as those with high-cardinality datasets, repeatedly recompute identical queries and hammer their backends. Trickster removes those redundant computations, making such environments significantly more performant and scalable. It replaces the need to hand-roll caching and load-balancing logic in front of HTTP applications by providing a fully featured proxy with an Application Load Balancer, pool autodiscovery, TLS termination, and a rules engine for custom request routing and rewriting.

Key capabilities

  • Provides an Application Load Balancer for time series and generic HTTP endpoints with pool autodiscovery from Kubernetes, AWS, GCP, Azure, Consul, Nomad, DNS, and more.
  • Supports TLS, HTTP/2 and HTTP/3 for frontend termination, TLS/HTTP/2 for backend origination, and automatic certificates from Let's Encrypt or any ACME certificate authority, including wildcard and on-demand issuance.
  • Operates as a Kubernetes Ingress and/or Gateway Controller.
  • Tunnels WebSocket and HTTP Upgrade connections, carries response trailers (gRPC), and delivers streaming responses incrementally.
  • Offers several caching layer options: in-memory, filesystem, Redis and bbolt, configurable down to the HTTP path via yaml settings.
  • Includes high-performance Collapsed Forwarding, Negative Caching to prevent domino-effect outages, and byte range request caching and acceleration.
  • Exports built-in Prometheus metrics, customizable health check endpoints, distributed tracing via OpenTelemetry over the OTLP protocol, and per-backend access and error logs in Apache-style customizable formats.

Who uses it and how

  • Teams running read-heavy dashboards against Prometheus, ClickHouse, InfluxDB, VictoriaMetrics, Apache Druid, Graphite, or GreptimeDB use it to eliminate redundant queries and speed chart rendering.
  • Platform operators deploying on Kubernetes use it as an Ingress and/or Gateway Controller, with pool autodiscovery sourced from the cluster.
  • Edge operators terminate TLS, HTTP/2 and HTTP/3 at Trickster and originate TLS/HTTP/2 to backends, with automatic ACME certificate issuance.
  • Organizations fronting static file servers and REST APIs use it as a general reverse proxy cache, including its built-in Static File Server for hosting websites and local content.
  • Security-conscious deployments restrict backends and paths by client location or source address using Geo ACLs and IP ACLs, across HTTP, native database and stream listeners.

Getting started

Trickster is distributed as the Docker image tricksterio/trickster on Docker Hub and is configured through yaml configuration files; documentation is available at https://trickstercache.org.

How it compares

Among similar tools named in these facts it has no direct counterpart: it combines a general-purpose HTTP reverse proxy cache with a TSDB query accelerator in a single binary, alongside an Application Load Balancer and Kubernetes Gateway Controller. Its CNCF sandbox status and Apache-2.0 licence place it among established cloud-native infrastructure projects rather than a single-purpose cache.

When to use it — and when not

A self-hoster must be prepared to operate and tune a yaml configuration covering chosen cache storage (in-memory, filesystem, Redis or bbolt), backend definitions, TLS/ACME settings, and monitoring endpoints such as Prometheus metrics and health checks. It is a poor fit for teams that need a turnkey solution with managed support or minimal operational surface, and for workloads with no dashboards or cacheable HTTP traffic. The README points to external docs for most features and a roadmap file for upcoming work, so evaluating specific capabilities requires reading those documents rather than the repository itself.

project readme (upstream, from github) — read inline

Follow on Twitter

License Coverage Status build status CII Best Practices GoDoc Docker Pulls Slack

Trickster is an HTTP reverse proxy/cache for http applications and a dashboard query accelerator for time series databases.

Learn more below, and check out our roadmap to find out what else is in the works.

Trickster is hosted by the Cloud Native Computing Foundation (CNCF) as a sandbox level project. If you are a company that wants to help shape the evolution of technologies that are container-packaged, dynamically-scheduled and microservices-oriented, consider joining the CNCF.

HTTP Reverse Proxy Cache

Trickster is a fully-featured Reverse Proxy Cache for HTTP applications like static file servers and REST APIs.

Feature Highlights

Time Series Database Accelerator

Trickster dramatically improves dashboard chart rendering times for end users by eliminating redundant computations on the TSDBs it fronts. In short, Trickster makes read-heavy Dashboard/TSDB environments, as well as those with high-cardinality datasets, significantly more performant and scalable.

Compatibility

Trickster works with virtually any Dashboard application that makes queries to any of these TSDBs:

How Trickster Accelerates Time Series

1. Time Series Delta Proxy Cache

Most dashboards request from a time series database the entire time range of data they wish to present, every time a user's dashboard loads, as well as on every auto-refresh. Trickster's Delta Proxy inspects the time range of a client query to determine what data points are already cached, and requests from the tsdb only the data points still needed to service the client request. This results in dramatically faster chart load times for everyone, since the tsdb is queried only for tiny incremental changes on each dashboard load, rather than several hundred data points of duplicative data.

2. Step Alignment

Time series databases group data into steps, or buckets, on a fixed grid. When a dashboard's time range starts or ends between two grid points, the bucket at that edge holds only part of its data. Trickster caches only complete buckets, so repeat and overlapping requests are fast and every viewer sees the same values, and each backend's step alignment mode decides what the client sees at the partial edges. Other tools call this aligning queries with their step; Trickster versions before 2.2 called it Step Boundary Normalization.

Mode At the partial edges
truncate the whole bucket at the start; none at the end
drop neither edge
partial both, holding only the rows inside the range, as the origin would answer
partial_start the start, holding only the rows inside the range
partial_end the whole bucket at the start, and the end, holding only the rows inside the range
off the origin's answer to the range as sent, cached as an object

Each provider defaults to the behavior it has always had, and a query can choose its own mode with a comment directive. See Step Alignment for the modes, their cost, and support by backend.

3. Fast Forward

Trickster's Fast Forward feature ensures that even with step alignment, real-time graphs still always show the most recent data, regardless of how far away the next step boundary is. For example, if your chart step is 300s, and the time is currently 1:21p, you would normally be waiting another four minutes for a new data point at 1:25p. Trickster will break the step interval for the most recent data point and always include it in the response to clients requesting real-time data. Fast Forward is Prometheus's partial_end step alignment mode, its default.

Trying Out Trickster

Check out our end-to-end Docker Compose demo composition for a zero-configuration running environment.

Installing

Docker

Docker images are available on Docker Hub (docker.io):

$ docker run --name trickster -d -v /path/to/trickster.yaml:/etc/trickster/trickster.yaml -p 0.0.0.0:8480:8480 trickstercache/trickster

Or via GitHub Container Registry (ghcr.io):

    $ docker run --name trickster -d -v /path/to/trickster.yaml:/etc/trickster/trickster.yaml -p 0.0.0.0:8480:8480 ghcr.io/trickstercache/trickster
Verifying Docker Image

To verify that the Trickster Docker image is running, first walk through the cosign quickstart guide.

To verify a trickster image, you can use the following command:

cosign verify ghcr.io/trickstercache/trickster:x.y.z --certificate-oidc-issuer=https://token.actions.githubusercontent.com --certificate-identity=https://github.com/trickstercache/trickster/.github/workflows/publish-image.yaml@refs/tags/vx.y.z

See the 'deploy' Directory for more information about using or creating Trickster docker images.

Kubernetes

The deploy/kube directory carries raw-YAML deployments of Trickster as a caching proxy and as a Kubernetes Gateway API / Ingress controller; see kubernetes-deploy.md, kubernetes-gateway.md and kubernetes-ingress.md.

Helm

Trickster Helm Charts are located at for installation, and maintained at . We welcome chart contributions.

Building from source

To build Trickster from the source code yourself you need to have a working Go environment with version 1.27 or greater installed.

You can directly use the go tool to download and install the trickster binary into your GOPATH:

    $ go install github.com/trickstercache/trickster/cmd/trickster@main
    # this starts a prometheus accelerator proxy for the provided endpoint
    $ trickster -origin-url http://prometheus.example.com:9090 -provider prometheus

You can also clone the repository yourself and build using make:

    $ mkdir -p $GOPATH/src/github.com/trickstercache
    $ cd $GOPATH/src/github.com/trickstercache
    $ git clone https://github.com/trickstercache/trickster.git
    $ cd trickster
    $ make build
    $ ./bin/trickster -origin-url http://prometheus.example.com:9090 -provider prometheus

The Makefile provides several targets, including:

  • build: build the trickster binary
  • docker: build a docker container for the current HEAD
  • clean: delete previously-built binaries and object files
  • test: runs unit tests
  • bench: runs benchmark tests
  • rpm: builds a Trickster RPM

More information

Refer to the docs directory or for additional info.

Contact

You can reach us on the #trickster channel on either the CNCF Slack Instance or the Gophers Slack Instance, or via Google Groups at .

Contributing

Refer to CONTRIBUTING.md


© 2021 The Linux Foundation. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page.

Frequently asked questions

Is trickster free to use?

trickster is open source under the Apache-2.0 licence. There is no licence fee and no seat count — you can self-host it or, where the project offers one, pay a vendor for a managed version instead.

What does trickster do?

Open Source HTTP Reverse Proxy Cache and Time Series DB Query Accelerator

What is trickster written in?

trickster is primarily written in Go. Its source is publicly available at https://github.com/trickstercache/trickster, and it has 2,092 GitHub stars.