Backend.AI App Proxy Worker
Purpose
The App Proxy Worker is a high-performance reverse proxy that routes user traffic to compute session services (Jupyter, SSH, TensorBoard, etc.) running on agents. It receives routing information from the Coordinator and handles SSL/TLS termination, load balancing, and traffic forwarding.
Key Responsibilities
1. Traffic Proxying
- Proxy HTTP/HTTPS requests to session services
- Proxy WebSocket connections for interactive services
- Handle SSL/TLS termination
- Stream responses efficiently
2. Route Resolution
- Receive routing tables from Coordinator
- Resolve session services from URLs
- Cache routing information locally
- Update routes dynamically
3. Health Checking
- Monitor backend service health
- Detect failed services
- Report health status to Coordinator
- Handle service failover
Architecture
1. Traffic Proxy (Main)
Framework: aiohttp + custom reverse proxy
Port: 5050 (default, HTTPS)
Protocol: HTTP/HTTPS, WebSocket
Key Features:
HTTP/HTTPS Proxy
- Route user requests to session services
- URL Pattern:
https://<worker-domain>/<session-id>/<service-name>/...
WebSocket Proxy
- Interactive service communication (Jupyter Kernel, SSH, etc.)
- Real-time log streaming
Key Characteristics:
- SSL/TLS termination (Let's Encrypt auto-certificate)
- High-performance async proxy
- Connection pooling and reuse
- Streaming support (large file downloads)
- Sticky session support
- Auto-retry and failover
Processing Flow:
HTTP Proxy Flow
User → HTTPS Request → Worker (SSL termination)
↓
Parse URL (extract session_id, service_name)
↓
Lookup route from local cache
↓
Resolve backend address (agent:port)
↓
Proxy request to agent
↓
Stream response back to user
WebSocket Proxy Flow
User → WS Upgrade Request → Worker
↓
Establish WS connection to agent
↓
Bidirectional message forwarding
2. REST API (Management)
Framework: aiohttp (async HTTP server)
Port: 6040 (default, separate management port)
Key Features:
- Communication with Coordinator
- Health check endpoints
- Metrics exposure (Prometheus)
- Internal management (no external access)
Component Interaction
Traffic Proxy Flow:
User (Browser) → Worker (Port 5050) → Kernel (on Agent)
│
├─ SSL/TLS termination
├─ Route resolution
└─ Traffic proxying
Management Flow:
Coordinator → Worker REST API (Port 6040) → Route updates
Metadata
Release files for backend.ai-appproxy-worker 26.8.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| backend_ai_appproxy_worker-26.8.3.tar.gz | 58.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| backend_ai_appproxy_worker-26.8.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 137.0 kB
Release files / backend_ai_appproxy_worker-26.8.3.tar.gz
| Download URL | backend_ai_appproxy_worker-26.8.3.tar.gz |
|---|---|
| Size | 58.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
d5f127159488bd929d9753c4f1ca805a72016a9bf77f6e191c6db4216136fdf1
|
|
BLAKE2b-256 checksum How to use checksums |
7b330e7b01680993d062c1b746e579c4e08997d80af7a2cb395675531ebba86a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.2.0 CPython/3.13.7
|
Release files / backend_ai_appproxy_worker-26.8.3-py3-none-any.whl
| Download URL | backend_ai_appproxy_worker-26.8.3-py3-none-any.whl |
|---|---|
| Size | 78.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
2eda53b555f98c8ad197498f608753d05a46307e357c0a898616031c42aa589b
|
|
BLAKE2b-256 checksum How to use checksums |
e616a9f4731555bebd430a53681317d0ebaade8e1ff069132a7c908e87b335ce
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.2.0 CPython/3.13.7
|