About this project

BunkerWeb is an open-source, cloud-native Web Application Firewall (WAF) that positions itself as a full-featured web server built on NGINX. Its stated goal is to protect web services so they are "secure by default", integrating as a reverse proxy into existing environments rather than requiring a separate installation step. Supported integrations include Linux (Debian, Ubuntu, Fedora, RHEL/CentOS/Rocky/AlmaLinux), Docker, Docker autoconf, Kubernetes, Docker Swarm and Microsoft Azure. Prebuilt Docker images are published for x64, x86, armv7 and arm64. For Kubernetes, an autoconf component acts as an Ingress controller and an official Helm chart is maintained in a separate repository. Configuration is driven by named settings (for example AUTO_LETS_ENCRYPT or USE_ANTIBOT), which can be supplied through environment variables, labels, or the web UI. A multisite mode allows a single instance or cluster to serve and protect multiple applications, each identified by a server name with its own settings. Custom NGINX and ModSecurity configurations can be included for cases that settings alone cannot cover. Security features described in the README include HTTPS with automated Let's Encrypt certificates, HTTP security headers and TLS hardening, an integrated ModSecurity WAF with the OWASP Core Rule Set, automatic banning based on HTTP status codes, connection and request limits, bot blocking via challenges (cookie, JavaScript, captcha, hCaptcha, reCAPTCHA), and blocking of known bad IPs through external blacklists and DNSBL. The project notes these are a non-exhaustive list and that tuning is recommended to manage false positives. Architecturally, a scheduler service stores settings and custom configurations in a backend database, executes jobs, and generates the configuration consumed by BunkerWeb instances. Supported databases are SQLite, MariaDB, MySQL and PostgreSQL. An optional web UI provides a graphical alternative to the CLI for managing instances and configurations, with an online read-only demo available. The project is licensed under AGPLv3. The README also describes commercial offerings: a managed BunkerWeb Cloud service, a PRO version with a 30-day trial and license key activation, and professional services such as technical support and consulting. PRO features are marked with a crown icon in the documentation and UI. Community resources include Discord, a forum, a threat map, and documentation sites.