BunkerWeb: NGINX-Based Open-Source WAF with Web UI
🛡️ Open-source and cloud-native Web Application Firewall (WAF)
At a glance
- What is it?
- BunkerWeb is an AGPL-3.0 Web Application Firewall built on NGINX that applies ModSecurity with the OWASP Core Rule Set, automatic Let's Encrypt HTTPS, and IP blacklists by default, deployable on Linux, Docker, Swarm, and Kubernetes.
- Who is it for?
- BunkerWeb is the right tool for teams that want a self-hosted WAF in front of existing web services without writing NGINX configuration from scratch, and who need an optional web UI for configuration management. The AGPL-3.0 license is a key constraint: any service that exposes BunkerWeb over a network to users must release the source of any modifications under the same license.
- Can I use it commercially?
- Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 5 days ago.
- What is it written in?
- Mainly Python, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.
Editorial analysis
WAF Built for Platform Engineers, Not Just Security Teams
BunkerWeb targets platform engineers and DevOps teams who deploy web services and need security enforced at the reverse proxy layer, before requests reach the application. The README frames it as making security the default state rather than something added after deployment.
The use case is teams who already run web services on Docker, Kubernetes, Docker Swarm, or bare Linux, and want to place a WAF in front of those services without building a custom NGINX configuration. BunkerWeb handles the NGINX configuration internally and exposes a settings interface (both CLI/config file and a web UI) for tuning rules and behavior.
The AGPL-3.0 license means BunkerWeb is free to deploy and modify, but any modification to the code that is made available over a network must be released under the same license. Teams evaluating a paid option can use BunkerWeb Cloud, a managed SaaS offering, through the Bunker Panel.
Security Features Built Into the Core
BunkerWeb's security defaults cover several categories:
HTTPS with Let's Encrypt automation: BunkerWeb handles certificate provisioning and renewal without manual certificate management steps. This works at the reverse proxy layer, so the upstream application does not need HTTPS configured separately.
ModSecurity WAF with the OWASP Core Rule Set: ModSecurity is an open-source WAF engine. The OWASP Core Rule Set (CRS) is a community-maintained set of rules covering common web attack categories including injection, cross-site scripting, and path traversal. BunkerWeb ships with both.
HTTP security headers and TLS hardening: BunkerWeb applies headers like Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options, and configures TLS to disable weak cipher suites and protocol versions. The exact headers and cipher lists are configurable.
Automatic IP banning: BunkerWeb monitors HTTP status codes from the upstream application. A client that generates an unusual rate of 4xx or 5xx responses is automatically banned. This handles some brute force and vulnerability scanning scenarios without manual rule creation.
Connection and request limits: BunkerWeb applies rate limiting at the connection and request level, configurable per service.
Bot challenges: clients that appear to be automated can be challenged with a cookie check, JavaScript execution test, CAPTCHA, hCaptcha, or reCAPTCHA. The appropriate challenge type depends on the deployment context.
IP blacklists and DNSBL: BunkerWeb checks connecting clients against external IP reputation lists and DNS-based blacklists.
Installing BunkerWeb with Docker
The README links to the documentation at docs.bunkerweb.io for full integration guides. The repository includes an examples directory with ready-made configurations for specific environments.
For Docker, the repository includes example compose files in `examples/docker-configs/`. A typical BunkerWeb Docker deployment requires the BunkerWeb container, a scheduler container that manages configuration and Let's Encrypt renewal, and the upstream application containers. Environment variables on each upstream container's service define which BunkerWeb security settings apply to that service.
The plugin system extends the core: additional security modules are installed as plugins. The Armory (referenced in the README as the plugin repository) provides extensions beyond the built-in feature set. The README links to both official plugin documentation and community plugin resources.
BunkerWeb is currently at version 1.6.15 for the stable release, with 1.6.16-rc2 available as a release candidate as of the most recent repository state. The project pushes frequently, with the last commit on 2026-09-25.
Limitations: AGPL Obligations and OWASP CRS Tuning
The AGPL-3.0 license is the most significant operational constraint. Unlike the MIT or Apache licenses, AGPL requires that organizations making BunkerWeb available as a network service release any modifications to the source code under the same license. This affects commercial service providers more than internal deployments, but it is a compliance consideration for any organization with strict license policies.
The OWASP Core Rule Set is known for producing false positives in applications that pass unusual but legitimate data through HTTP parameters. A standard web form that accepts HTML content, a JSON API that accepts nested structures, or an application that uses unusual URL encoding can trigger CRS rules and return 403 responses to real users. Tuning the CRS requires either adding per-rule exclusions or switching specific rules to detection-only mode. The README does not document the tuning workflow inline; it links to the security tuning section of the documentation.
BunkerWeb's ModSecurity integration adds latency to every request, since each request is inspected before being forwarded to the upstream. The magnitude depends on the number of active rules and the hardware, but it is a real cost for high-throughput services.
BunkerWeb Against Traefik and Cloudflare
Traefik is a cloud-native reverse proxy and load balancer written in Go. It handles HTTPS with Let's Encrypt and integrates with Docker and Kubernetes label-based routing. Traefik does not include a built-in WAF. Adding WAF capabilities to Traefik requires a commercial Traefik Enterprise license or a third-party middleware plugin. BunkerWeb includes a WAF by default.
Cloudflare is a commercial CDN and security platform that operates as a network-layer service in front of origin servers. Its WAF is managed, requires no infrastructure, and provides a global distributed network. BunkerWeb is self-hosted and runs on infrastructure the user manages. The relevant difference is operational model: Cloudflare offloads infrastructure management but requires routing traffic through Cloudflare's network, while BunkerWeb runs on the user's own servers and keeps traffic local.
For teams that want the security properties of a WAF without paying for Cloudflare or Traefik Enterprise, and who are comfortable managing their own infrastructure, BunkerWeb provides the ModSecurity engine and OWASP CRS with a configuration interface that does not require hand-writing NGINX configuration files.
Editorial conclusion
BunkerWeb is the right tool for teams that want a self-hosted WAF in front of existing web services without writing NGINX configuration from scratch, and who need an optional web UI for configuration management. The AGPL-3.0 license is a key constraint: any service that exposes BunkerWeb over a network to users must release the source of any modifications under the same license. Teams that want SaaS-managed security should look at BunkerWeb Cloud or commercial alternatives. Before deploying, review the OWASP Core Rule Set tuning requirements for your specific application, since the default ruleset blocks legitimate traffic in applications that pass unusual characters in form data.
Frequently asked questions
What is BunkerWeb?
BunkerWeb is an open-source NGINX-based Web Application Firewall that acts as a reverse proxy with security features enabled by default, including ModSecurity with the OWASP Core Rule Set, Let's Encrypt automation, IP blacklists, and bot challenges. It deploys on Linux, Docker, Docker Swarm, and Kubernetes.
How do you install BunkerWeb?
BunkerWeb is deployed as a Docker container, as a Linux package, or in Kubernetes. The documentation at docs.bunkerweb.io provides integration guides for each environment. The repository's `examples/` directory contains ready-made Docker Compose configurations for specific stacks.
Is BunkerWeb free?
BunkerWeb is free and open-source under the AGPL-3.0 license. There is also a managed SaaS offering called BunkerWeb Cloud with professional support, available through the Bunker Panel, which is a paid service.
How does BunkerWeb compare to NGINX?
Plain NGINX is a web server and reverse proxy with no built-in security ruleset. BunkerWeb runs on top of NGINX and adds ModSecurity, the OWASP Core Rule Set, HTTP security headers, automatic HTTPS, IP blacklisting, and bot challenges. BunkerWeb manages the NGINX configuration internally so users interact with its own settings interface instead of writing NGINX config files directly.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/bunkerity-bunkerweb)