One command, then your own config
Install with a single line, then test the config file you already have. No converter or new configuration language; evaluate the result on a spare port before cutover.
Public Beta · Friends don't let friends C the socket
Serve faster.
21% more requests per second over TLS, at 0.70× the CPU each.
Serve safer.
Written in Rust. The bug class behind 40 of the 62 advisories in nginx's own list cannot be written here.
Bring your nginx config.
Keep the configuration language, routing rules and operational commands you already know.
Run anywhere.
Signed apt and rpm packages across seven architectures, from Raspberry Pi to IBM Z.
curl -fsSL https://xinproxy.com/install.sh | sh Enrols the signed apt or rpm repository and installs beside your existing server. Starts nothing on its own. Read the script · Getting started
xin is an HTTP web server, reverse proxy, load balancer with a memory-safe core. The beta reads nginx configuration and ships the proxy as one binary with no module ABI to patch. Kubernetes Gateway is available in Private Beta.
Why xin
Install with a single line, then test the config file you already have. No converter or new configuration language; evaluate the result on a spare port before cutover.
Signed apt and rpm repositories covering amd64, arm64, i686, ARMv6/v7, ppc64le and s390x — verified back to CentOS 7 and Debian 8. Static musl builds for Alpine and distroless.
21% more TLS requests per second on 30% less CPU each, measured against nginx 1.26.3 on pinned cores. Cleartext and static serving hold parity.
The HTTP engine, config engine and resolver contain no unsafe code, enforced by the compiler. Buffer overflows and use-after-frees are not bugs you can write here.
Free for non-commercial use. Running it in production at a company? We offer commercial licensing and support straight from the people who wrote it.
Performance
Against nginx 1.26.3 on the same machine: physical cores pinned, three interleaved rounds, counterbalanced order. Each panel has its own scale — the four workloads span 632 to 367,961 per second.
Safety
That is nginx's own published list: buffer overflows, use-after-frees, memory disclosure — seventeen years of them, still arriving in 2026. It is the defect class Rust removes as a category, and the reason xin exists.
nginx security advisories that are memory-safety defects
Talk to us
Get beta support, discuss commercial licensing, or request access to the Kubernetes Gateway private beta. Submissions are stored in our own database and reviewed by the engineering team.