
BunkerWeb
Web application firewall and security reverse proxy

BunkerWeb is a security-focused web server and reverse proxy designed to protect web applications with a built-in Web Application Firewall (WAF) and hardened defaults. It is typically deployed in front of one or more HTTP applications (as a reverse proxy) and can be managed via a web-based UI and configuration templates.
Key Features
- NGINX-based reverse proxy/web server with security-first default configuration
- Integrated WAF capabilities (commonly deployed with ModSecurity + OWASP Core Rule Set)
- Web UI for configuration and operational management
- Automated TLS certificate management (ACME/Let’s Encrypt) for HTTPS enablement
- IP/geo-based access controls and request filtering features (e.g., allow/deny lists)
- Rate limiting and protections targeting common OWASP Top 10 attack patterns
- Container-friendly deployment options (Docker) for homelabs and production setups
Use Cases
- Put a WAF in front of self-hosted services (e.g., dashboards, CMS, admin panels)
- Centralize HTTPS and security controls for multiple internal web applications
- Add request filtering, rate limiting, and hardened headers to legacy apps
Limitations and Considerations
- Full protection depends on correct rule tuning (WAF rules can cause false positives)
- Advanced scenarios may require NGINX/WAF knowledge for optimal configuration
BunkerWeb is a practical option for teams and self-hosters who want an NGINX-based reverse proxy with an integrated WAF and a management UI. It focuses on providing common web security controls in a deployable package while keeping compatibility with typical reverse-proxy architectures.
Categories:
Tags:
Tech Stack:
Similar Services

Pi-hole
Network-wide ad blocking via DNS sinkhole
DNS sinkhole that blocks ads, trackers, and malicious domains network-wide with a web dashboard, per-client controls, and optional DHCP/DNS features.

CyberChef
The Cyber Swiss Army Knife for data analysis and decoding
Browser-based tool for decoding, encoding, encryption, and data analysis using a drag-and-drop “recipe” workflow for security, DFIR, and engineering tasks.

AdGuard Home
Network-wide ads and tracker blocking via DNS
Self-hosted DNS server with ad/tracker blocking, custom filtering, parental controls, encrypted DNS, and per-client statistics for home networks.

Nginx Proxy Manager
Web UI for Nginx reverse proxy with Let's Encrypt SSL
Web-based reverse proxy manager for Nginx with hosts, streams, access lists, and automatic Let's Encrypt certificates via an easy admin UI.

SafeLine
Self-hosted WAF for protecting web apps and APIs
SafeLine is an open-source web application firewall (WAF) that protects web apps and APIs from common attacks using HTTP traffic inspection, rules, and management UI.


Teleport
Identity-native infrastructure access for SSH, Kubernetes, RDP and DBs
Open-source platform that provides unified, audited, identity-based access to servers, Kubernetes clusters, databases, and desktops without static credentials.
TLS
Bash