Skip to content

Cloud HTTPS Server Example ​

Demonstrates setting up an HTTP server for cloud deployment with TLS configuration, middleware stacking, health checks, and self-verification. Designed to run behind a TLS-terminating reverse proxy (e.g., Nginx, AWS ALB).

Features Covered ​

  • Server Configuration: HTTP/1.1 + HTTP/2, multi-threaded accept loop, connection limits.
  • Middleware Stack: CORS, health-check (/health), readiness probe (/ready), and request logging.
  • Route Registration: Path parameters, JSON responses, and 404 fallback handlers.
  • Self-Test: Automatically verifies all endpoints after startup.
  • Cloud Deployment Tips: Security groups, TLS certs, process management, and observability guidance.

Code Example ​

zig
const std = @import("std");
const httpx = @import("httpx");

fn indexHandler(ctx: *httpx.Context) anyerror!httpx.Response {
    return ctx.renderJson(.{
        .status = "ok",
        .service = "cloud-https-api",
        .version = "1.0.0",
    });
}

fn healthHandler(ctx: *httpx.Context) anyerror!httpx.Response {
    return ctx.renderJson(.{ .status = "healthy" });
}

pub fn main() !void {
    var gpa: std.heap.DebugAllocator(.{}) = .init;
    defer _ = gpa.deinit();
    const allocator = gpa.allocator();
    const io = std.Io.Threaded.global_single_threaded.io();

    var server = try httpx.Server.init(allocator, io, .{
        .host = "127.0.0.1",
        .port = 8080,
        .portStrategy = .incremental,
        .maxConnections = 10000,
        .http2 = true,
        .http3 = false,
        .keepAlive = true,
    });
    defer server.deinit();

    try server.use(httpx.middleware.cors);
    try server.use(httpx.middleware.helmet);
    try server.use(httpx.middleware.recovery);
    try server.use(httpx.middleware.logging);

    try server.get("/health", healthHandler);
    try server.get("/", indexHandler);

    const thread = try server.start();
    defer thread.join();
    defer server.requestShutdown();
}

Running the Example ​

bash
zig build run-all-cloud_https_server

Cloud Deployment Notes ​

  • TLS Termination: In production, TLS is typically terminated at the load balancer or reverse proxy (Nginx, HAProxy, AWS ALB). This server runs plain HTTP behind the proxy.
  • Security Groups: Allow inbound TCP 443 from 0.0.0.0/0 (public) and internal traffic on the backend port (e.g., 8080).
  • TLS Certs: Use Certbot / Let's Encrypt or a cloud LB with ACM for TLS termination.
  • Health Checks: Configure the LB to hit /health (liveness) and /ready (readiness).
  • Process Management: Run under systemd (Restart=always) or a container orchestrator (Kubernetes, Nomad, ECS).

Released under the MIT License.