An open-source, next-generation Web Application Firewall (WAF) based on NGINX that makes web services secure by default.
BunkerWeb is an open-source, next-generation Web Application Firewall (WAF) built on NGINX that acts as a reverse proxy to protect web applications from attacks. It integrates seamlessly into various environments like Docker, Kubernetes, and Linux, providing comprehensive security features such as HTTPS automation, ModSecurity WAF, bot blocking, and IP blacklisting out of the box.
DevOps engineers, system administrators, and security professionals who need to secure web services across on-premises, cloud, or containerized environments with minimal configuration overhead.
Developers choose BunkerWeb for its 'secure by default' approach, extensive plugin ecosystem, and flexible deployment options that eliminate the need for complex, manual security setups while offering enterprise-grade protection.
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Integrates natively with Linux, Docker, Kubernetes, Swarm, and Azure, as detailed in the 'Integrations' section, making it versatile for diverse infrastructures.
Includes HTTPS automation with Let's Encrypt, ModSecurity WAF, and bot challenges enabled by default, providing 'secure by default' protection without manual setup.
Offers official plugins like ClamAV and Coraza to extend functionality, allowing tailored security enhancements beyond core features.
Provides an optional, user-friendly web UI for configuration and monitoring, reducing reliance on CLI as highlighted in the 'Web UI' section.
Requires configuring multiple components like a scheduler and database backend (e.g., SQLite, PostgreSQL), which can be daunting and error-prone for initial deployment.
The AGPLv3 license may compel source code disclosure for modifications, posing legal hurdles for some commercial or proprietary use cases.
Only a handful of official plugins are available, which might not cover all niche security needs compared to more established WAF solutions.