Very bizarre, never seen that before.
Thumbprints:
- 60949a09aab8677f87a0b9eda7099a03ca510fb3
- 1b146798f0dc93773247e86312f1b730c4eeebb3For my own stuff that's not meant for a wider audience, I sometimes use mTLS in front of my apps, alongside self-signed certs (my own CA) that shouldn't show up in certificate transparency logs.
This site also seems to be requesting a certificate from the user. Normally you probably don't want that for public facing resources.
https://github.com/losfair/zeroserve/blob/main/CADDY_COMPAT....
AFAIK eBPF can be hardware offloaded. If you have the use case.
If you limit the scope, its worth doing and might not take as much effort as you might think. You could possibly find some enjoyment and learn a few things doing so.
People that trully need performance are not going to use a random server that has 0 support/ track record.
The usual 3400 lines lock file and AGENTS.md raise some questions about the aforementioned security, though.