21 tunnel

The tunnel for AI agents.

Visit Website
August 7, 2026 Why We Rewrote the Tunnel Stack in Rust

Most tunneling services use Go. It makes sense: Go has a mature networking ecosystem, fast builds, and simple cross-compilation.

So why did we choose Rust for 21Tunnel?

The short answer: we wanted the compiler to help us build a more reliable tunnel server.

The Problem

A tunnel server handles TLS connections, public HTTP requests, authentication, and traffic routing.

A single failure can affect multiple customers on the same node. A panic, memory issue, or unexpected input shouldn't bring down an entire tunnel service.

Rust gave us stronger guarantees around these failure modes.

Why Rust?

From day one, we enabled an aggressive lint configuration.

We use:

  • #![forbid(unsafe_code)]

  • No unwrap()

  • No expect()

  • No panic!

  • No todo!

  • Strict Clippy checks

The goal wasn't to write “perfect” code. It was to make entire categories of mistakes harder to introduce.

For a networking product where reliability matters, that trade-off made sense.

Why We Didn't Use QUIC

Our first prototype used QUIC, but we eventually moved to TCP + TLS + Yamux.

The main reasons were practical:

  • TCP/443 works better across restrictive networks.

  • The resulting binary was significantly smaller.

  • TCP + TLS is easier to troubleshoot with familiar networking tools.

For a tunnel client that needs to work from laptops, corporate networks, mobile connections, and public Wi-Fi, boring infrastructure can sometimes be the better choice.

The Trade-Off

Rust isn't free.

We experienced:

  • Longer build times

  • A smaller hiring pool

  • A steeper learning curve

  • Some frustrating lifetime and middleware errors

Our release builds take minutes rather than seconds.

But we accepted those costs because reliability and explicit failure handling were more important to us than fast compilation.

What We Learned

The biggest lesson wasn't simply “Rust is better than Go.”

It's that technology choices should follow the failure modes of your product.

For 21Tunnel, networking reliability, predictable failure handling, and a small deployable agent mattered enough to justify Rust.

And because the project is open source, developers can inspect the implementation and see exactly how those decisions were made.

Read the full engineering story: Why we rewrote the tunnel stack in Rust.

Comment

About

21Tunnel exists because the team wanted to solve a problem they felt existing tunneling tools didn't fully address: developers increasingly need tunnels that they can control, self-host, automate, and use across teams .