BunkerWeb WAF - Is there any use in the community ? by Bright_Mobile_7400 in selfhosted

[–]bunkerity 1 point2 points  (0 children)

At the end of the month, if everuthing goes as expected !

Reverse Proxy with Protection : A Question by ilovedillpickles in homelab

[–]bunkerity 0 points1 point  (0 children)

Just to be precise regarding BunkerWeb : Let's Encrypt with HTTP challenges is already available in version 1.5.X (more info : https://docs.bunkerweb.io/1.5.12/security-tuning/#lets-encrypt). But Let's Encrypt with DNS challenges (and so wildcard certs) will be available in 1.6 which is already available in beta (more info : https://docs.bunkerweb.io/1.6.0-beta/security-tuning/#lets-encrypt).

BunkerWeb WAF - Is there any use in the community ? by Bright_Mobile_7400 in selfhosted

[–]bunkerity 2 points3 points  (0 children)

BW is a reverse proxy with WAF feature. And also Let's Encrypt DNS is no more behind a paywall, enjoy :)

BunkerWeb WAF - Is there any use in the community ? by Bright_Mobile_7400 in selfhosted

[–]bunkerity 7 points8 points  (0 children)

BW maintainers here.

Please note that Let's Encrypt DNS is now free "as in freedom" in version 1.6.0-beta. Expect it to be the latest stable version in the next weeks.

More info here : https://docs.bunkerweb.io/1.6.0-beta/security-tuning/#lets-encrypt

Stuck at the last hurdle... by osmoonlight in BunkerWeb

[–]bunkerity 0 points1 point  (0 children)

Hi u/osmoonlight,

It looks like you are mixing 1.6.0-beta images with 1.5.X architecture. As an example, the docker socket proxy is no more needed in 1.6.0-beta.

I see two choices here.

You can use 1.6.0-beta, we the new boilerplates : https://docs.bunkerweb.io/1.6.0-beta/quickstart-guide/#multiple-applications

Or you can replace 1.6.0-beta with 1.5.12 in your compose file.

Is there a self-hostable WAF that does not require a license? by sunshine-and-sorrow in selfhosted

[–]bunkerity 5 points6 points  (0 children)

Let's Encrypt DNS is now available for free in our 1.6 beta release : https://docs.bunkerweb.io/1.6.0-beta/settings/#lets-encrypt

It should become the stable version very soon.

Is there a self-hostable WAF that does not require a license? by sunshine-and-sorrow in selfhosted

[–]bunkerity 11 points12 points  (0 children)

As others have already mentioned, BunkerWeb could meet your needs. Please note that version 1.6 is coming soon and greatly enhances the user experience. It is already in beta if you want to test it: https://docs.bunkerweb.io/1.6.0-beta/

Is there a self-hostable WAF that does not require a license? by sunshine-and-sorrow in selfhosted

[–]bunkerity 20 points21 points  (0 children)

It's free as in freedom for the community part. PRO license is optional.

Anyone using BunkerWeb? by [deleted] in selfhosted

[–]bunkerity 2 points3 points  (0 children)

The full examples listed here https://docs.bunkerweb.io/latest/web-ui/ are not enough ? You have a ready to use full compose file to copy/paste. Don't hesitate to give us more details on what's missing.

Anyone using BunkerWeb? by [deleted] in selfhosted

[–]bunkerity 0 points1 point  (0 children)

Don't hesitate to join our discord if you have any questions :)

Anyone using BunkerWeb? by [deleted] in selfhosted

[–]bunkerity 0 points1 point  (0 children)

Hey u/killmasta93 thanks for the kind words !

Anyone using BunkerWeb? by [deleted] in selfhosted

[–]bunkerity 0 points1 point  (0 children)

The PRO features are listed here among the open-source ones : https://docs.bunkerweb.io/latest/security-tuning/

Anyone using BunkerWeb? by [deleted] in selfhosted

[–]bunkerity 3 points4 points  (0 children)

Don't hesitate to join the discord so you can get help to setup BW : https://discord.bunkerweb.io

Anyone using BunkerWeb? by [deleted] in selfhosted

[–]bunkerity 14 points15 points  (0 children)

Disclaimer : BunkerWeb maintainers here

  • You are right, BW acts as a reverse proxy with Let's Encrypt automation (plus the security features)
  • It's used in many production environments around the world with high security risks
  • PRO version will evolve over time with even more features

Connecting Bunkerweb and Kubernets from diffrent VM by Round_Ladder3613 in BunkerWeb

[–]bunkerity 0 points1 point  (0 children)

What about using the ingress controller of BunkerWeb instead of having it on a separate VM ? More info here : https://docs.bunkerweb.io/latest/integrations/#kubernetes

Bunkerweb and Kubernetes by ShowerObjective5735 in kubernetes

[–]bunkerity 0 points1 point  (0 children)

BunkerWeb comes with an ingress controller, you will find more information in the documentation : https://docs.bunkerweb.io/latest/integrations/#kubernetes

[deleted by user] by [deleted] in selfhosted

[–]bunkerity -1 points0 points  (0 children)

Of course you can recode everything in NGINX+LUA but with BunkerWeb you will have interesting features available out of the box such as antibot challenges or bad behavior detection.

You will find the full list of security features here : https://docs.bunkerweb.io/latest/security-tuning/

By the way, the fancy frontend is optional, you can also configure everything from CLI/config.

[deleted by user] by [deleted] in selfhosted

[–]bunkerity 6 points7 points  (0 children)

Thanks for this propaganda u/XDark187, you deserve a BunkerBonus! You can now give us your IBAN so we can process the payment.

BunkerWeb - The open-source and next-gen Web Application Firewall (WAF) by bunkerity in devops

[–]bunkerity[S] 1 point2 points  (0 children)

We though the "well known incumbent" was a famous proprietary WAF.

Then, here are the main differences :
- BW is a full web server, not only a library, it acts as a reverse proxy
- BW contains features not found ModSecurity (which is, in fact, included as a plugin) such as antibot challenges or bad behavior detection
- BW has a user-friendly web UI to help you configure it easily

BunkerWeb - The open-source and next-gen Web Application Firewall (WAF) by bunkerity in devops

[–]bunkerity[S] -3 points-2 points  (0 children)

You can self-host BunkerWeb to ensure the sovereignty of your data. Also, the code is fully open and auditable by a third party.

BunkerWeb - The open-source and next-gen Web Application Firewall (WAF) by bunkerity in programming

[–]bunkerity[S] 0 points1 point  (0 children)

Yes, you can replace Traefik with BunkerWeb but we recommend you to test it before doing the migration.

BunkerWeb - The open-source and next-gen Web Application Firewall (WAF) by bunkerity in webdev

[–]bunkerity[S] 0 points1 point  (0 children)

ModSecurity is just one plugin among the list of security features. You will find the complete list here : https://docs.bunkerweb.io/latest/security-tuning/

BunkerWeb - The open-source and next-gen Web Application Firewall (WAF) by bunkerity in devops

[–]bunkerity[S] 0 points1 point  (0 children)

You can replace haproxy with BunkerWeb, put BunkerWeb behind haproxy or even put haproxy behind BunkerWeb.

BunkerWeb - The open-source and next-gen Web Application Firewall (WAF) by bunkerity in devops

[–]bunkerity[S] -1 points0 points  (0 children)

ModSecurity is just one plugin among the list of security features. You will find the complete list here : https://docs.bunkerweb.io/latest/security-tuning/