// the find
orbien-org/orbien
A lightweight high-performance intranet penetration tool with ~5MB binary size. Supports multiple transport and application protocols for proxying. Provides pure Rust native cross-platform desktop client and server web UI
Orbien is a Rust/Tokio reverse-proxy tunnel for exposing internal services through NAT, in the same space as frp or ngrok's OSS competitors. It's aimed at self-hosters and small teams who want a single lightweight binary for tunneling TCP/UDP/HTTP/SOCKS5 traffic, with a native desktop GUI and a Java client for Spring Boot shops instead of shelling out to a CLI.
Transport layer actually offers real choices — TCP, KCP, WebSocket and QUIC with yamux multiplexing — rather than the single-transport approach most frp clones ship. The desktop client is built with Slint instead of wrapping Electron, which explains the small binary size and is a deliberate, unusual choice for a Rust GUI. Security is built into core rather than bolted on: token auth has a dedicated replay-protection module (core/src/auth/replay.rs), and HTTPS supports client-side TLS termination, not just passthrough. The JVM ecosystem gets first-class treatment via a Netty-based client plus a Spring Boot starter with autoconfiguration, which is more integration work than most Rust infra projects bother with.
The benchmark comparisons against frp are self-reported, run on loopback only, by the maintainers — no independent numbers, and loopback hides the packet-loss/jitter behavior that matters most for KCP and QUIC transports. 'NAT traversal' in the tagline is misleading: this is relay-through-a-public-server architecture like frp, not STUN/hole-punching P2P traversal, and the README never clarifies that distinction. No mention of test coverage or CI beyond a basic ci.yml badge — for something handling auth tokens and TLS termination, that's a gap worth checking before trusting it with anything internet-facing. The Java client and Spring Boot starter are a second implementation of the wire protocol (see client-java/MsgCodec.java vs core/src/msg/codec.rs) maintained separately from the Rust core, which is a classic place for protocol drift to bite you on a version bump.