The Ngris Blog
Tunneling & Edge Gateway Blog
Engineering articles, tutorials, and product deep-dives on API gateways, secure tunneling, and edge computing.
RSS feedIris Knows Your Account: an AI Account Assistant
Iris is an AI account assistant: ask about your own endpoints, traffic, usage, and certificates and it answers from live account data, read-only.
Let Iris Take Action, Safely — Behind a Confirm Gate
Iris can create, update, and delete real resources — but every AI action needs your confirmation: a before-and-after diff and a blast-radius preview first.
Generate Traffic-Policy Rules With AI
Describe the behavior in plain English and Iris drafts a traffic-policy rule — WAF, JA3 bot management, CORS, JWT validation, caching — for you to review.
Analyze Traffic Logs With AI
Analyze traffic logs with AI: get a per-request explanation of why a request was blocked or allowed, and search your logs in plain English.
One-Command AI Account Report
Ask Iris for an AI account report: a structured, exportable summary of your endpoints, traffic, posture, and certs — built from real reads, never fabricated.
Hands-Off Firewall Autonomy That Auto-Reverts
Opt-in AI autonomous security: for firewall rules only, Iris can apply a safe, reversible change after a passing dry-run — and auto-revert if it hurts real traffic.
Generate Firewall Rules With AI
Describe what to block in plain English and Iris drafts the firewall rule — the right traffic-policy phase and match — for you to review before it enforces.
Generate Rate Limit Rules With AI
Say the limit in plain English — 10 login attempts per minute per IP — and Iris drafts the rate-limit rule, scoped to the right endpoint, for you to review.
Proactive Alerts: Catch Cert Expiry Before It Causes Downtime
Iris surfaces proactive alerts before problems bite: a certificate near expiry, usage burning toward a plan limit, or an endpoint exposed without a WAF.
Iris: an AI Assistant Built Into Your Gateway
Iris is the AI built into Ngris: ask how-to questions, generate firewall and rate-limit rules from plain English, and get proactive alerts before things break.
Put a Custom Domain on Localhost (with Automatic HTTPS)
Point a custom domain at your local or tunneled service with automatic HTTPS — reserve a hostname, add a CNAME to cname.ngris.io, then run one command.
Expose a Local API to the Internet
Expose a local API to the internet with a public HTTPS URL, then lock it down with auth, rate limits, and a WAF — and inspect every call. Not just a tunnel.
Your Tunnel Is Now a Full API Gateway
A traffic-policy engine runs 23 rule types across four ordered phases at the edge — WAF, JWT, mTLS, rate limits, and CEL-guarded transforms — attached per endpoint, where the first non-continue result wins.
Ship a Web Application Firewall in One Rule
A Coraza-powered WAF you attach as a single traffic-policy rule — detect by default, block when you're ready, with a curated in-binary baseline and room for your own SecLang.
Catch Bots at the TLS Handshake with JA3
JA3 fingerprints the TLS ClientHello before a single HTTP byte is parsed — computed only when you've enabled a bot-management rule, matched against a denylist or allowlist you build from your own detect logs.
Turn Your OpenAPI Spec Into Edge Request Validation
Upload or paste an OpenAPI 3 spec and Ngris generates one body-validation rule per JSON operation — SSRF-safe parsing, a full preview, and rules staged disabled so an import can't break production.
Deploy Edge Security Rules Without Breaking Prod
Detect-first defaults, staged spec imports, and a blast-radius preview that replays your own real traffic through a rule before you save it — so a typo doesn't take prod down.
Edge Computing Security: Best Practices for 2026
Secure tunnel connections, WAF, identity-aware access, and live traffic inspection — a practical guide to edge computing security with zero-trust architecture.
Tunneling vs API Gateway vs Edge Computing: What's the Difference?
Tunneling, API gateways, and edge computing solve different problems. Learn when to use each — and how Ngris combines all three in one platform from dev to production.
Identity-Aware Access: SSO for Internal Services Without a VPN
Put an internal dashboard behind your identity provider in minutes. Users sign in with Google, GitHub, or Okta; Ngris enforces who can reach what at the edge — no VPN, no shared password.
Debug Production Traffic: Live Inspection and Request Replay
“It only happens in prod” is usually a request you can't reproduce. Capture the exact one, filter to it, and replay it against a fixed build until it's green.
Test Webhooks Locally with a Public URL
Stripe, GitHub, and Shopify all want to POST to a public HTTPS URL. Point them at your laptop, watch every delivery in real time, and replay the ones that failed.
Expose Localhost to the Internet with a Public URL
Expose localhost to the internet in one command: turn localhost:3000 into a public HTTPS URL to share on your phone or a teammate — no port forwarding, no DNS.
Static Egress IPs Explained
A partner says “send us your IP and we'll allowlist it.” Behind a shared edge, that IP isn't stable. A static egress IP makes your outbound traffic come from one address you can hand over with confidence.
Ngris on Kubernetes, Without the YAML Spaghetti
A native operator with ten CRDs, an Ingress shim, and Gateway API support — so you can declare endpoints, traffic policies, and mTLS the same way you declare everything else in your cluster.
Shipping Mutual TLS at the Edge
Certificate-based client authentication on every Ngris endpoint — across HTTPS, HTTP/2, and HTTP/3.
Building an Edge Gateway: From Zero to Production
A practical guide to setting up a production-grade edge gateway with WAF, per-endpoint auth, load balancing, and multi-region deployment in under an hour.
Ngris vs Traditional Tunneling: A Feature-by-Feature Comparison
An honest, detailed comparison of Ngris and traditional tunneling tools across protocols, security, pricing, and developer experience. See where each platform excels.
Why We Built Ngris
The story behind Ngris — why existing tunneling tools weren't enough, and how we designed a platform that grows with you from development to production.