BunkerWeb is a next-generation, open-source Web Application Firewall (WAF) built on top of Nginx. It secures your web services out of the box, automatically configuring security features such as HTTPS certificates, HTTP security headers, access control, and bot protection — with a simple, human-readable configuration format.
Web Application Firewall — built-in ModSecurity-compatible rules block SQL injection, XSS, and other attacks
HTTP security headers — enforces CSP, HSTS, X-Frame-Options, and more
Access control — IP/geolocation whitelists and blacklists plus authentication
Bot & bruteforce protection — rate limiting and anomaly detection against automated attacks
Reverse proxy — routes traffic to backend applications and services
Cloud-native — Docker, Docker Compose, and Kubernetes deployment with a web UI
Highly configurable — declarative YAML-style configuration for every security feature
Why Use BunkerWeb?
BunkerWeb gives you enterprise-grade web protection without the complexity of manually hardening a proxy. It wraps the battle-tested Nginx engine with sensible secure defaults, so deploying a protected web service takes minutes rather than days of security tuning.
Use Cases
Protecting self-hosted web apps and dashboards exposed to the internet
Adding a WAF layer in front of existing web servers and containers
Automating HTTPS and security headers for multiple services
Docker and Kubernetes deployments needing per-service security policies