Trickster is an HTTP reverse proxy/cache for http applications and a dashboard query accelerator for time series databases.

Learn more below, and check out our roadmap to find out what else is in the works.
Trickster is hosted by the Cloud Native Computing Foundation (CNCF) as a sandbox level project. If you are a company that wants to help shape the evolution of technologies that are container-packaged, dynamically-scheduled and microservices-oriented, consider joining the CNCF.
HTTP Reverse Proxy Cache
Trickster is a fully-featured Reverse Proxy Cache for HTTP applications like static file servers and REST APIs.
Feature Highlights
- A unique and powerful Application Load Balancer for Time Series and generic HTTP endpoints, with pool autodiscovery from Kubernetes, AWS, GPC, Azure, Consul, Nomad, DNS, and more
- Supports TLS, HTTP/2 and HTTP/3 for frontend termination, and TLS/HTTP/2 for backend origination
- Automatic certificates from Let's Encrypt or any ACME certificate authority, including wildcard and on-demand issuance
- Can serve as Kubernetes Ingress and/or Gateway Controller
- WebSocket and HTTP Upgrade tunneling, response trailers (gRPC), and incremental delivery of streaming responses
- Offers several options for a caching layer, including in-memory, filesystem, Redis and bbolt
- Highly customizable, using simple yaml configuration settings, down to the HTTP Path
- Built-in Prometheus metrics and customizable Health Check Endpoints for end-to-end monitoring
- Negative Caching to prevent domino effect outages
- High-performance Collapsed Forwarding
- Best-in-class Byte Range Request caching and acceleration
- Distributed Tracing via OpenTelemetry, supporting OTLP protocol
- Per-backend Access and Error Logs with Apache-style customizable formats
- Rules engine for custom request routing and rewriting
- Built-in Static File Server for hosting websites and other local content
- Geo ACLs and IP ACLs restrict backends and paths by client location, on HTTP, native database and stream listeners alike
Time Series Database Accelerator
Trickster dramatically improves dashboard chart rendering times for end users by eliminating redundant computations on the TSDBs it fronts. In short, Trickster makes read-heavy Dashboard/TSDB environments, as well as those with high-cardinality datasets, significantly more performant and scalable.
Compatibility
Trickster works with virtually any Dashboard application that makes queries to any of these TSDBs:
How Trickster Accelerates Time Series
1. Time Series Delta Proxy Cache
Most dashboards request from a time series database the entire time range of data they wish to present, every time a user's dashboard loads, as well as on every auto-refresh. Trickster's Delta Proxy inspects the time range of a client query to determine what data points are already cached, and requests from the tsdb only the data points still needed to service the client request. This results in dramatically faster chart load times for everyone, since the tsdb is queried only for tiny incremental changes on each dashboard load, rather than several hundred data points of duplicative data.

2. Step Alignment
Time series databases group data into steps, or buckets, on a fixed grid. When a dashboard's time range starts or ends between two grid points, the bucket at that edge holds only part of its data. Trickster caches only complete buckets, so repeat and overlapping requests are fast and every viewer sees the same values, and each backend's step alignment mode decides what the client sees at the partial edges. Other tools call this aligning queries with their step; Trickster versions before 2.2 called it Step Boundary Normalization.
| Mode | At the partial edges |
|---|---|
truncate |
the whole bucket at the start; none at the end |
drop |
neither edge |
partial |
both, holding only the rows inside the range, as the origin would answer |
partial_start |
the start, holding only the rows inside the range |
partial_end |
the whole bucket at the start, and the end, holding only the rows inside the range |
off |
the origin's answer to the range as sent, cached as an object |
Each provider defaults to the behavior it has always had, and a query can choose its own mode with a comment directive. See Step Alignment for the modes, their cost, and support by backend.

3. Fast Forward
Trickster's Fast Forward feature ensures that even with step alignment, real-time graphs still always show the most recent data, regardless of how far away the next step boundary is. For example, if your chart step is 300s, and the time is currently 1:21p, you would normally be waiting another four minutes for a new data point at 1:25p. Trickster will break the step interval for the most recent data point and always include it in the response to clients requesting real-time data. Fast Forward is Prometheus's partial_end step alignment mode, its default.

Trying Out Trickster
Check out our end-to-end Docker Compose demo composition for a zero-configuration running environment.
Installing
Docker
Docker images are available on Docker Hub (docker.io):
$ docker run --name trickster -d -v /path/to/trickster.yaml:/etc/trickster/trickster.yaml -p 0.0.0.0:8480:8480 trickstercache/trickster
Or via GitHub Container Registry (ghcr.io):
$ docker run --name trickster -d -v /path/to/trickster.yaml:/etc/trickster/trickster.yaml -p 0.0.0.0:8480:8480 ghcr.io/trickstercache/trickster
Verifying Docker Image
To verify that the Trickster Docker image is running, first walk through the cosign quickstart guide.
To verify a trickster image, you can use the following command:
cosign verify ghcr.io/trickstercache/trickster:x.y.z --certificate-oidc-issuer=https://token.actions.githubusercontent.com --certificate-identity=https://github.com/trickstercache/trickster/.github/workflows/publish-image.yaml@refs/tags/vx.y.z
See the 'deploy' Directory for more information about using or creating Trickster docker images.
Kubernetes
The deploy/kube directory carries raw-YAML deployments of Trickster as a caching proxy and as a Kubernetes Gateway API / Ingress controller; see kubernetes-deploy.md, kubernetes-gateway.md and kubernetes-ingress.md.
Helm
Trickster Helm Charts are located at for installation, and maintained at . We welcome chart contributions.
Building from source
To build Trickster from the source code yourself you need to have a working Go environment with version 1.27 or greater installed.
You can directly use the go tool to download and install the trickster
binary into your GOPATH:
$ go install github.com/trickstercache/trickster/cmd/trickster@main
# this starts a prometheus accelerator proxy for the provided endpoint
$ trickster -origin-url http://prometheus.example.com:9090 -provider prometheus
You can also clone the repository yourself and build using make:
$ mkdir -p $GOPATH/src/github.com/trickstercache
$ cd $GOPATH/src/github.com/trickstercache
$ git clone https://github.com/trickstercache/trickster.git
$ cd trickster
$ make build
$ ./bin/trickster -origin-url http://prometheus.example.com:9090 -provider prometheus
The Makefile provides several targets, including:
- build: build the
tricksterbinary - docker: build a docker container for the current
HEAD - clean: delete previously-built binaries and object files
- test: runs unit tests
- bench: runs benchmark tests
- rpm: builds a Trickster RPM
More information
Refer to the docs directory or for additional info.
Contact
You can reach us on the #trickster channel on either the CNCF Slack Instance or the Gophers Slack Instance, or via Google Groups at .
Contributing
Refer to CONTRIBUTING.md
© 2021 The Linux Foundation. All rights reserved. The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page.