Backend.AI App Proxy Worker
Purpose
The App Proxy Worker is a high-performance reverse proxy that routes user traffic to compute session services (Jupyter, SSH, TensorBoard, etc.) running on agents. It receives routing information from the Coordinator and handles SSL/TLS termination, load balancing, and traffic forwarding.
Key Responsibilities
1. Traffic Proxying
- Proxy HTTP/HTTPS requests to session services
- Proxy WebSocket connections for interactive services
- Handle SSL/TLS termination
- Stream responses efficiently
2. Route Resolution
- Receive routing tables from Coordinator
- Resolve session services from URLs
- Cache routing information locally
- Update routes dynamically
3. Health Checking
- Monitor backend service health
- Detect failed services
- Report health status to Coordinator
- Handle service failover
Architecture
1. Traffic Proxy (Main)
Framework: aiohttp + custom reverse proxy
Port: 5050 (default, HTTPS)
Protocol: HTTP/HTTPS, WebSocket
Key Features:
HTTP/HTTPS Proxy
- Route user requests to session services
- URL Pattern:
https://<worker-domain>/<session-id>/<service-name>/...
WebSocket Proxy
- Interactive service communication (Jupyter Kernel, SSH, etc.)
- Real-time log streaming
Key Characteristics:
- SSL/TLS termination (Let's Encrypt auto-certificate)
- High-performance async proxy
- Connection pooling and reuse
- Streaming support (large file downloads)
- Sticky session support
- Auto-retry and failover
Processing Flow:
HTTP Proxy Flow
User → HTTPS Request → Worker (SSL termination)
↓
Parse URL (extract session_id, service_name)
↓
Lookup route from local cache
↓
Resolve backend address (agent:port)
↓
Proxy request to agent
↓
Stream response back to user
WebSocket Proxy Flow
User → WS Upgrade Request → Worker
↓
Establish WS connection to agent
↓
Bidirectional message forwarding
2. REST API (Management)
Framework: aiohttp (async HTTP server)
Port: 6040 (default, separate management port)
Key Features:
- Communication with Coordinator
- Health check endpoints
- Metrics exposure (Prometheus)
- Internal management (no external access)
Component Interaction
Traffic Proxy Flow:
User (Browser) → Worker (Port 5050) → Kernel (on Agent)
│
├─ SSL/TLS termination
├─ Route resolution
└─ Traffic proxying
Management Flow:
Coordinator → Worker REST API (Port 6040) → Route updates
Metadata
Release files for backend.ai-appproxy-worker 26.8.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| backend_ai_appproxy_worker-26.8.2.tar.gz | 58.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| backend_ai_appproxy_worker-26.8.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 136.9 kB
Release files / backend_ai_appproxy_worker-26.8.2.tar.gz
| Download URL | backend_ai_appproxy_worker-26.8.2.tar.gz |
|---|---|
| Size | 58.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
b3dd25c95784a112b643303a65978cace6833e40f4845ff2742fbac82e8119d0
|
|
BLAKE2b-256 checksum How to use checksums |
f60225df740bd3c5e8ac4a020eff1236c35433265c805d5da90c87bec57ad3e9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.2.0 CPython/3.13.7
|
Release files / backend_ai_appproxy_worker-26.8.2-py3-none-any.whl
| Download URL | backend_ai_appproxy_worker-26.8.2-py3-none-any.whl |
|---|---|
| Size | 78.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fecb773999ee0cc3ad40d975c3439c35f7280806658bb3f51799e572eaad1d5d
|
|
BLAKE2b-256 checksum How to use checksums |
a4dc3a4b223405831f11c61d97a63e484ae4b45bab5a97959fe5ce1bed5b3778
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.2.0 CPython/3.13.7
|