Features
coreX Manager provides a complete control plane for edge proxies with over 20 feature areas spanning security, traffic management, performance, observability, and AI agent integration.
Core
Dashboard
Real-time HAProxy stats: CPU, memory, connections, requests. Preview and apply config changes. Unique ID decoder.
Learn more →Global Options
HAProxy global/defaults directives, JA4 TLS fingerprinting, HTTP request fingerprinting, compression/cache/transform toggles.
Learn more →Listeners
HTTP/2, QUIC/HTTP3, TLS, Proxy Protocol, gRPC, JSON-RPC. Per-listener backend rules, response headers, WAF attachment.
Learn more →Backends
Load balancing algorithms (roundrobin, leastconn, source, uri, static-rr), sticky sessions, health checks, FastCGI support.
Learn more →Security
Security Lists
Named collections of IP/CIDR, ASN, GeoIP country codes, and JA4 TLS fingerprints. Dynamic feeds auto-refresh from remote sources.
Learn more →Security Rules
Ordered first-match-wins rules with the coreX expression language. Actions: block, allow, redirect, custom response, skip rules/WAF/rate-limit.
Learn more →Risk Scoring
Request-phase scoring engine with multiple rulesets, signed integer points, 0-99 clamped scores, and density-based amplification. Scores are available to Security Rules.
Learn more →WAF
OWASP CRS, custom SecRules, remote rule sets with SHA256 verification, per-rule version snapshots, conditional exceptions, SIEM forwarding.
Learn more →CAPTCHA
Challenge actions for WAF, security, and rate limit rules. Three providers: Native (proof-of-work), reCAPTCHA, and Turnstile. Client-bound tokens.
Learn more →API Armor
GraphQL query analysis, JSON schema validation, JWT/API-key auth validation, multi-dimensional behavioral profiling, per-endpoint rate limiting.
Learn more →Page Protect
Content Security Policy management, security headers, script allowlisting, CSP violation reporting.
Learn more →Traffic
Rate Limiting
Stick-table based sliding-window limits. Per-listener, per-endpoint, per-user-agent scoping. Burst control, block durations (tarpit), WAF-triggered limits.
Learn more →Redirects & Rewrites
Drag-and-drop ordered URL redirects (permanent, temporary, regex) and rewrites. Per-listener scoping with path prefix or regex matching.
Learn more →Response Headers
Set, override, add, or delete response headers with optional HAProxy ACL conditions. Per-listener and per-backend scoping.
Learn more →Performance
Caching
Two-tier cache: HAProxy native memory cache (L1) + Varnish disk cache (L2). Cacheability rules with path/filename/extension matching. PURGE/BAN support.
Learn more →Compression
Per-backend Brotli, Zstd, Gzip, Deflate, and raw-deflate compression via Rust Lua module. Configurable quality, level, content types, and offload mode.
Learn more →Response Transforms
Replace, inject, and mask response body content. Mask mode supports tokenize (Valkey-backed) and encrypt (AES-256-GCM) for PII protection.
Learn more →Image Conversion
On-the-fly JPEG/PNG/GIF to WebP conversion via Rust Lua filter. Content negotiation based on Accept header. Lossless for PNG, lossy for JPEG/GIF.
Learn more →SSL/TLS
Certificates
Let's Encrypt issuance (HTTP-01 and DNS challenge), custom certificate uploads, automatic renewal. Per-listener certificate assignment.
Learn more →Cipher Suites
Predefined baselines: FIPS, FedRAMP, PCI, Modern, and Custom. HSTS options. Per-listener cipher suite selection.
Learn more →Observability
Metrics
HAProxy process info and stats sampled every 30 seconds. WAF event metrics with breakdowns by action, rule ID, severity, and message. Recharts visualizations.
Learn more →Logging
JSON access logs with risk scores, WAF actions, rate limit actions, and security rule actions. Configurable log destinations and logged fields.
Learn more →Audit Events
Records config mutations, auth events, and config lifecycle actions (apply/revert/rollback). Events linked to config snapshots. CSV export.
Learn more →WAF Logs
Expandable log rows with full Coraza event details: rule ID, severity, message, client IP, URI, action. Inline search filtering.
Learn more →Management
Users
Multi-user support with admin/read-only roles. TOTP 2FA. JWT-based authentication with token blocklist via Valkey.
Learn more →Settings
Runtime theme switching with 6 built-in themes and custom theme editor. 18 customizable colors. Global feature toggles.
Learn more →Snapshots
Config snapshots capture the full HAProxy config state. Revert to any previous snapshot. Audit events linked to snapshots.
Learn more →Custom Pages
Custom error pages for 403/429/500 responses. Template variables for request ID, WAF ID, rate limit details.
Learn more →MCP Gateway
Expose the control plane as MCP tools for AI agents. Policy engine, DLP, guardrails, rate limiting, and skills management.
Learn more →