// the find
gamemann/xdp-proxy
A stateless, high-performance NAT-like proxy that attaches to the XDP hook in the Linux kernel using (e)BPF for fast packet processing. This proxy forwards packets based on configurable rules and performs source-port mapping, similar to IPTables and NFTables.
A stateless XDP/eBPF packet proxy that does L3/L4 forwarding with source-port mapping, attaching at the XDP hook to run ahead of the normal netfilter path. Aimed at people doing high-throughput or low-latency Linux packet forwarding who'd otherwise reach for iptables/nftables DNAT rules but want to stay in kernel-bypass-adjacent territory.
Attaching at DRV-mode XDP means forwarding decisions happen before SKB allocation, which is a real latency win over netfilter-based NAT, not just a marketing claim. Pinned BPF maps plus separate xdpfwd-add/xdpfwd-del CLI tools let you add or remove forward rules on a running instance without restarting the proxy or losing existing port mappings. Runtime config supports periodic reload from disk (update_time), so most rule changes don't require a rebuild, only the truly structural stuff (like raising MAX_FWD_RULES) needs recompilation. CI actually builds the project on every push, which is more than a lot of BPF projects bother with.
Kernel requirements are a trap: you need 5.3+ for general BPF loop support and realistically 6.4+ for bpf_loop()'s open-coded iterators, and if you're stuck below that you have to hand-edit config.h and live with a hardcoded ~21 concurrent source ports, which defeats a lot of the point of source-port mapping. The forward rule cap (256, MAX_FWD_RULES) is a compile-time constant, not something you can bump without a rebuild and redeploy. There's no test suite in the repo, CI only checks that it compiles, so correctness of the actual NAT/port-mapping logic is unverified beyond manual testing. It's a single-maintainer project and genuinely stateless, meaning no connection tracking, so calling it 'NAT-like' undersells how much less it does than a real NAT gateway — fine for straightforward TCP/UDP/ICMP forwarding, not a safe drop-in for anything relying on connection state.