finds.dev← search

// the find

orbien-org/orbien

★ 1,283 · Rust · Apache-2.0 · updated Sep 2026

A lightweight high-performance intranet penetration tool with ~5MB binary size. Supports multiple transport and application protocols for proxying. Provides pure Rust native cross-platform desktop client and server web UI

Orbien is a Rust/Tokio reverse-proxy tunnel for exposing internal services through NAT, in the same space as frp or ngrok's OSS competitors. It's aimed at self-hosters and small teams who want a single lightweight binary for tunneling TCP/UDP/HTTP/SOCKS5 traffic, with a native desktop GUI and a Java client for Spring Boot shops instead of shelling out to a CLI.

Transport layer actually offers real choices — TCP, KCP, WebSocket and QUIC with yamux multiplexing — rather than the single-transport approach most frp clones ship. The desktop client is built with Slint instead of wrapping Electron, which explains the small binary size and is a deliberate, unusual choice for a Rust GUI. Security is built into core rather than bolted on: token auth has a dedicated replay-protection module (core/src/auth/replay.rs), and HTTPS supports client-side TLS termination, not just passthrough. The JVM ecosystem gets first-class treatment via a Netty-based client plus a Spring Boot starter with autoconfiguration, which is more integration work than most Rust infra projects bother with.

The benchmark comparisons against frp are self-reported, run on loopback only, by the maintainers — no independent numbers, and loopback hides the packet-loss/jitter behavior that matters most for KCP and QUIC transports. 'NAT traversal' in the tagline is misleading: this is relay-through-a-public-server architecture like frp, not STUN/hole-punching P2P traversal, and the README never clarifies that distinction. No mention of test coverage or CI beyond a basic ci.yml badge — for something handling auth tokens and TLS termination, that's a gap worth checking before trusting it with anything internet-facing. The Java client and Spring Boot starter are a second implementation of the wire protocol (see client-java/MsgCodec.java vs core/src/msg/codec.rs) maintained separately from the Rust core, which is a classic place for protocol drift to bite you on a version bump.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →