# BunkerWeb: NGINX-Based Open-Source WAF with Web UI

> BunkerWeb is an AGPL-3.0 Web Application Firewall built on NGINX that applies ModSecurity with the OWASP Core Rule Set, automatic Let's Encrypt HTTPS, and IP blacklists by default, deployable on Linux, Docker, Swarm, and Kubernetes.

**bunkerity/bunkerweb** — 🛡️ Open-source and cloud-native Web Application Firewall (WAF)

- Repository: https://github.com/bunkerity/bunkerweb
- Website: https://www.bunkerweb.io
- Stars: 11,003 · Forks: 643
- Language: Python
- License: AGPL-3.0
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/bunkerity-bunkerweb

## WAF Built for Platform Engineers, Not Just Security Teams

BunkerWeb targets platform engineers and DevOps teams who deploy web services and need security enforced at the reverse proxy layer, before requests reach the application. The README frames it as making security the default state rather than something added after deployment.

The use case is teams who already run web services on Docker, Kubernetes, Docker Swarm, or bare Linux, and want to place a WAF in front of those services without building a custom NGINX configuration. BunkerWeb handles the NGINX configuration internally and exposes a settings interface (both CLI/config file and a web UI) for tuning rules and behavior.

The AGPL-3.0 license means BunkerWeb is free to deploy and modify, but any modification to the code that is made available over a network must be released under the same license. Teams evaluating a paid option can use BunkerWeb Cloud, a managed SaaS offering, through the Bunker Panel.

## Security Features Built Into the Core

BunkerWeb's security defaults cover several categories:

HTTPS with Let's Encrypt automation: BunkerWeb handles certificate provisioning and renewal without manual certificate management steps. This works at the reverse proxy layer, so the upstream application does not need HTTPS configured separately.

ModSecurity WAF with the OWASP Core Rule Set: ModSecurity is an open-source WAF engine. The OWASP Core Rule Set (CRS) is a community-maintained set of rules covering common web attack categories including injection, cross-site scripting, and path traversal. BunkerWeb ships with both.

HTTP security headers and TLS hardening: BunkerWeb applies headers like Strict-Transport-Security, Content-Security-Policy, and X-Frame-Options, and configures TLS to disable weak cipher suites and protocol versions. The exact headers and cipher lists are configurable.

Automatic IP banning: BunkerWeb monitors HTTP status codes from the upstream application. A client that generates an unusual rate of 4xx or 5xx responses is automatically banned. This handles some brute force and vulnerability scanning scenarios without manual rule creation.

Connection and request limits: BunkerWeb applies rate limiting at the connection and request level, configurable per service.

Bot challenges: clients that appear to be automated can be challenged with a cookie check, JavaScript execution test, CAPTCHA, hCaptcha, or reCAPTCHA. The appropriate challenge type depends on the deployment context.

IP blacklists and DNSBL: BunkerWeb checks connecting clients against external IP reputation lists and DNS-based blacklists.

## Installing BunkerWeb with Docker

The README links to the documentation at docs.bunkerweb.io for full integration guides. The repository includes an examples directory with ready-made configurations for specific environments.

For Docker, the repository includes example compose files in `examples/docker-configs/`. A typical BunkerWeb Docker deployment requires the BunkerWeb container, a scheduler container that manages configuration and Let's Encrypt renewal, and the upstream application containers. Environment variables on each upstream container's service define which BunkerWeb security settings apply to that service.

The plugin system extends the core: additional security modules are installed as plugins. The Armory (referenced in the README as the plugin repository) provides extensions beyond the built-in feature set. The README links to both official plugin documentation and community plugin resources.

BunkerWeb is currently at version 1.6.15 for the stable release, with 1.6.16-rc2 available as a release candidate as of the most recent repository state. The project pushes frequently, with the last commit on 2026-09-25.

## Limitations: AGPL Obligations and OWASP CRS Tuning

The AGPL-3.0 license is the most significant operational constraint. Unlike the MIT or Apache licenses, AGPL requires that organizations making BunkerWeb available as a network service release any modifications to the source code under the same license. This affects commercial service providers more than internal deployments, but it is a compliance consideration for any organization with strict license policies.

The OWASP Core Rule Set is known for producing false positives in applications that pass unusual but legitimate data through HTTP parameters. A standard web form that accepts HTML content, a JSON API that accepts nested structures, or an application that uses unusual URL encoding can trigger CRS rules and return 403 responses to real users. Tuning the CRS requires either adding per-rule exclusions or switching specific rules to detection-only mode. The README does not document the tuning workflow inline; it links to the security tuning section of the documentation.

BunkerWeb's ModSecurity integration adds latency to every request, since each request is inspected before being forwarded to the upstream. The magnitude depends on the number of active rules and the hardware, but it is a real cost for high-throughput services.

## BunkerWeb Against Traefik and Cloudflare

Traefik is a cloud-native reverse proxy and load balancer written in Go. It handles HTTPS with Let's Encrypt and integrates with Docker and Kubernetes label-based routing. Traefik does not include a built-in WAF. Adding WAF capabilities to Traefik requires a commercial Traefik Enterprise license or a third-party middleware plugin. BunkerWeb includes a WAF by default.

Cloudflare is a commercial CDN and security platform that operates as a network-layer service in front of origin servers. Its WAF is managed, requires no infrastructure, and provides a global distributed network. BunkerWeb is self-hosted and runs on infrastructure the user manages. The relevant difference is operational model: Cloudflare offloads infrastructure management but requires routing traffic through Cloudflare's network, while BunkerWeb runs on the user's own servers and keeps traffic local.

For teams that want the security properties of a WAF without paying for Cloudflare or Traefik Enterprise, and who are comfortable managing their own infrastructure, BunkerWeb provides the ModSecurity engine and OWASP CRS with a configuration interface that does not require hand-writing NGINX configuration files.

## Conclusion

BunkerWeb is the right tool for teams that want a self-hosted WAF in front of existing web services without writing NGINX configuration from scratch, and who need an optional web UI for configuration management. The AGPL-3.0 license is a key constraint: any service that exposes BunkerWeb over a network to users must release the source of any modifications under the same license. Teams that want SaaS-managed security should look at BunkerWeb Cloud or commercial alternatives. Before deploying, review the OWASP Core Rule Set tuning requirements for your specific application, since the default ruleset blocks legitimate traffic in applications that pass unusual characters in form data.

## FAQ

### What is BunkerWeb?

BunkerWeb is an open-source NGINX-based Web Application Firewall that acts as a reverse proxy with security features enabled by default, including ModSecurity with the OWASP Core Rule Set, Let's Encrypt automation, IP blacklists, and bot challenges. It deploys on Linux, Docker, Docker Swarm, and Kubernetes.

### How do you install BunkerWeb?

BunkerWeb is deployed as a Docker container, as a Linux package, or in Kubernetes. The documentation at docs.bunkerweb.io provides integration guides for each environment. The repository's `examples/` directory contains ready-made Docker Compose configurations for specific stacks.

### Is BunkerWeb free?

BunkerWeb is free and open-source under the AGPL-3.0 license. There is also a managed SaaS offering called BunkerWeb Cloud with professional support, available through the Bunker Panel, which is a paid service.

### How does BunkerWeb compare to NGINX?

Plain NGINX is a web server and reverse proxy with no built-in security ruleset. BunkerWeb runs on top of NGINX and adds ModSecurity, the OWASP Core Rule Set, HTTP security headers, automatic HTTPS, IP blacklisting, and bot challenges. BunkerWeb manages the NGINX configuration internally so users interact with its own settings interface instead of writing NGINX config files directly.

## Sources

- [bunkerity/bunkerweb on GitHub](https://github.com/bunkerity/bunkerweb)
- [License: AGPL-3.0](https://github.com/bunkerity/bunkerweb/blob/master/LICENSE)
- [Project website](https://www.bunkerweb.io)
- [README](https://github.com/bunkerity/bunkerweb/blob/master/README.md)
- [Releases](https://github.com/bunkerity/bunkerweb/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/bunkerity-bunkerweb
