The Gaps coreX Fills
HAProxy can enforce almost any decision you can write. Cloudflare will make the decision for you, at their edge, with a score you cannot replay.
The hole in the middle is the product.
Not “another managed ruleset.” Not a prettier haproxy.cfg. A control plane that turns a proxy people already trust into something a security team can operate: versioned policy, explainable scores, WAF events you can act on, API contracts, challenges, and logs that land in your SIEM.
That is what coreX is for.
Two different holes
I keep splitting this the same way I split it when people ask “what is still missing?”
HAProxy-specific gaps are about Community HAProxy as a security product. It is a world-class proxy. It is not a WAAP. ACLs and stick-tables are not CRS, not a challenge action, not a false-positive workflow, and not an analyst UI.
Commercial WAAP gaps (Cloudflare and peers) are about ownership. They virtual-patch zero-days the morning a CVE drops. They soak volumetric junk on someone else’s anycast. They also terminate your TLS, sample your events, cap payload inspection, and make multi-app policy feel like one zone pretending to be a portfolio.
coreX is software you run. It is not a global network. It fills the first hole almost end-to-end, and it fills the ownership side of the second. It does not pretend to be 330 cities.
What HAProxy leaves on the table
Community HAProxy inspects and routes. It does not ship a WAF. You bolt Coraza or ModSecurity on with SPOA, or you buy Enterprise and get an in-process ML engine you cannot read.
That split creates the rest of the list:
- Policy lives in a config file, not a security object with paranoia per app, exceptions, and rollback.
- Challenge actions in OSS are “deny, tarpit, or write Lua.”
- Bot identity is a kit — JA4, header anomalies, ASN maps — not a labeled catalog.
- Positive security (OpenAPI, GraphQL, “this field must never appear”) is homework.
- The response path is second-class. Request ACLs are first-class.
- Observability is proxy stats. Analysts live in
grepand Prometheus. - gRPC / GraphQL / QUIC security policy lags the HTTP/1.1 ACL story.
HAProxy Enterprise closes some of this if you pay and accept a closed engine. Community users rebuild pale copies. I got tired of rebuilding them.
What cloud WAAPs leave on the table
Cloud platforms are good at the thing only a planetary network can do. They are weaker at the thing a proxy you own should be good at.
Payload and framing. Inspection caps and fail-open on oversized bodies are a performance choice. Padding and “too big, skip it” still work. Independent tests and vendor changelogs have said the quiet part out loud for years.
You do not own the decision. TLS ends on their box. Bot scores are opaque. A bad managed-rule or feature-file push is everyone’s incident. Replay is a sampled dashboard, not your packet capture.
Multi-app policy is a dashboard problem. One zone, hundreds of apps, different false-positive budgets. Teams invent an orchestration layer on the vendor API. That is the gap.
Custom logic is thinner than a real proxy. Expression languages are fine until you need protocol gymnastics, response mutation, or per-backend exceptions that HAProxy ACLs do in one pass.
Client-side and response-side lag request-side. SQLi on the way in is table stakes. JS supply chain, response DLP, and origin error leakage are extras.
The commercial pattern: strong virtual patching and global soak. Weak ownership. Weak large-payload honesty. A control plane built for “a website,” not “ninety subsidiaries with different risk budgets.”
The map
Gap is the capability. Who ships it is who already has the feature today — Community HAProxy, a typical cloud WAAP, both, or neither. The last column is how coreX closes it.
| Gap | Who ships the feature | What coreX does |
|---|---|---|
| Application WAF on the Community HAProxy path | Cloud WAAP; HAProxy Enterprise | Coraza + OWASP CRS + custom SecRules + remote rule sets with SHA256 + per-rule snapshots + exceptions + SIEM |
| Managed TLS certificates (ACME) without giving up termination | Cloud WAAP, because they hold your TLS | Certificates — HTTP-01 served by HAProxy itself, DNS-01 plugins, auto-renew, hot-swap into listeners |
| Security policy as an object (not a config file) | Cloud WAAP | Ordered security rules, expression language, first-match-wins, skip-WAF / skip-rate-limit actions |
| Explainable, local risk score | Neither | Risk scoring 0–99 from request-phase rulesets; scores are first-class inputs to security rules |
| Challenge actions (PoW / CAPTCHA / Turnstile) | Cloud WAAP; HAProxy Enterprise | Native proof-of-work, Turnstile, reCAPTCHA, bound to WAF / security / rate-limit rules |
| Client identity you can list and score (JA4, fingerprints, feeds) | Cloud WAAP (catalog); neither as a local list primitive | JA4 lists, HTTP request fingerprinting, ASN / Geo / IP feeds that auto-refresh |
| API contract enforcement (schema / GraphQL / JWT) | Cloud WAAP on higher tiers | API Armor: JSON schema, GraphQL query analysis, JWT / API-key checks, per-endpoint behavior |
| Response-side and client-side controls | Cloud WAAP on higher tiers | Response transforms (replace / inject / mask, tokenize or AES-256-GCM), headers, Page Protect CSP + script allowlists |
| Modern compression (Brotli / zstd) on the proxy path | Cloud WAAP; Community HAProxy ships gzip only | Per-backend compression — brotli, zstd, gzip, deflate with per-algorithm tuning |
| Edge image optimization (on-the-fly WebP) | Cloud WAAP, usually a paid SKU | Image conversion — JPEG/PNG/GIF to WebP on Accept negotiation, size-guarded, cached |
| Real HTTP caching on the proxy path | Cloud WAAP (core product); Community HAProxy ships a token RAM cache | Two-tier cache — HAProxy L1 memory + disk L2 with first-match cacheability rules |
| Security-event UX (rule, payload context, exception from the row) | Cloud WAAP | WAF event UI with rule ID, severity, message, URI; exception-from-log; metrics by action and rule |
| Snapshot, diff, rollback, and policy-as-code | Cloud WAAP (API); neither as a full local snapshot plane | Snapshots, diff, revert, audit events, Terraform provider (50+ resources) |
| Data plane and full logs stay on your network | Community HAProxy | Same trust model, with WAF events and request logs to your Vector sinks — not a sampled vendor pane |
| Decisions you can replay (not an opaque edge score) | Neither | Local scores and full events. You sample only if you choose to. |
| Complete-body inspection policy (no vendor fail-open cap) | Neither as a default | You set the body policy. Inspect or reject. No 128KB “skip it” decision made elsewhere. |
| Per-app policy for a portfolio of apps | Neither well | Listeners, per-listener WAF attach, lists, rules, and IaC instead of one zone pretending to be a fleet |
| Agent loop on live policy + SIEM | Neither as a shipped loop | MCP server + MCP gateway so an agent can read rules, query the SIEM, and write policy in one conversation |
That last row is not decoration. It is the loop I actually use: ask the agent what got through, get a rule, apply a snapshot. I wrote that up in Targeted Attacks that Slip by in the Noise.
What this looks like in the product
The stack is not a mystery. HAProxy is the data plane. Coraza is the WAF engine. Varnish is the disk cache behind HAProxy’s in-memory L1. Vector ships logs. coreX is the plane that generates, validates, snapshots, and hot-reloads the lot from a GUI, a REST API, and Terraform.
On the request path that means:
- Listener policy (HTTP/2, QUIC, TLS, per-listener WAF attach).
- Security lists — IP/CIDR, ASN, Geo, JA4 — including feeds you do not babysit.
- Risk score, then first-match security rules.
- Rate limits on stick-tables, with WAF-triggered limits and tarpit durations.
- Coraza / CRS, with exceptions you can create from a log row.
- API Armor when the route is an API, not a website.
- Cache, compression, response transforms, Page Protect on the way out.
None of that required a DNS cutover to a third party. None of it requires trusting a model you cannot inspect to be the only brain.
Honesty about what we do not fill
Two gaps are still engineering, not UI.
Coraza over SPOA is still out-of-process. Community HAProxy has no in-process WAF hook. SPOE can fire on HEADERS before DATA arrives, which is a real HTTP/2 body-timing class. A control plane does not delete that. Buffer-complete bodies before the agent — or an in-process engine — is the next data-plane fight, not a checkbox we pretend is done.
We are not an anycast network. Cloudflare and Akamai sell cities. coreX sells software. Volumetric L3/L4 still lands on your NICs. Instant vendor virtual patches for every framework 0-day still come from people who see twenty percent of the web. You can point coreX at remote rule sets. You do not get their observation graph for free.
Also not a miracle: a labeled residential-proxy catalog, a 30-day SOC events product at Enterprise-cloud depth, or “change one DNS record and walk away.”
If a feature only works because someone else terminates TLS on five continents, it does not belong on this list. I already wrote the longer competitor matrix in coreX vs Cloudflare, Akamai, F5, and HAProxy.
The feature I would still build next
A local, explainable, protocol-correct decision engine that:
- inspects the complete request and the response in-process
- fails closed on an undeclared API field because the contract is in the proxy
- computes client signals you can reproduce (JA4, HTTP fingerprint, TLS, replay)
- treats cloud intel as a feed, not as the brain
- says why in a form a human or an agent can turn into a snapshot
That is the remaining hole between “HAProxy can do anything if you are an expert” and “the edge will decide, opaquely.” coreX is the closest I have gotten to shipping the second half without giving away the first.
Who this is for
You already run HAProxy, or you are done renting a proxy you cannot see.
You have more than one app and you are tired of one managed ruleset fighting all of them.
You want CRS, schema checks, JA4 lists, and a challenge action in the same apply.
You want the agent in the same conversation as the policy and the SIEM.
You do not want the request body in someone else’s memory.
If that is you, start at the features page and the quick start. Turn on WAF and one list on a non-production listener. Take a snapshot you trust. Then add API Armor and the MCP gateway.
Correct what matters. On your infrastructure.
coreX Platform — Correct What Matters. One proxy. Multiple directions. Zero blind spots.