NetGoat logo

NetGoat

Website

Self-hostable reverse proxy and traffic manager with WAF features

890 stars 47 forks last commit first released AGPL-3.0

Actively maintained

Last commit 29 Jul 2026.

NetGoat screenshot

NetGoat is a self-hostable reverse proxy engine and traffic manager designed to provide Cloudflare-like controls for routing, security, and performance. It aims to help homelabs and teams manage inbound web traffic with an integrated UI and rule-based behavior.

Key Features

  • Reverse proxy for HTTP traffic, including WebSocket support
  • TLS termination with automated certificate handling
  • WAF-style request filtering and anti-abuse protections
  • Rate limiting and request queuing to protect APIs and apps
  • Load balancing and failover for multi-node routing
  • Per-domain configuration with wildcard/regex support
  • Dynamic rules engine for custom routing and filtering logic
  • Metrics dashboard for traffic and error visibility
  • Optional integration targeting Cloudflare workflows (such as tunnels)

Use Cases

  • Fronting multiple self-hosted services with a single security and routing layer
  • Adding rate limiting and basic WAF protections to APIs and web apps
  • Managing multi-service homelab ingress with per-domain policies and monitoring

Limitations and Considerations

  • Project is explicitly work-in-progress; features and stability may change significantly
  • Some advertised capabilities may be incomplete depending on the current release state

NetGoat is best suited for users who want a centralized, UI-driven reverse proxy with security-focused controls and extensibility. As it matures, it can serve as a flexible edge layer for both homelab and small-team deployments.

Categories:

Tags:

Tech Stack:

Share:

Similar to NetGoat

Wiredoor logo

Wiredoor

Ingress-as-a-service to expose private services via WireGuard and NGINX

1.6k
77
Last commit

Self-hosted ingress platform that exposes internal HTTP/TCP services to the internet through reverse WireGuard tunnels, with NGINX routing and automatic TLS certificates.

Apache-2.0Actively maintained
Alternative to:
ngrok logo
ngrok
+13
BunkerWeb logo

BunkerWeb

Open-source web application firewall and reverse proxy

10.9k
640
Last commit

BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.

AGPL-3.0Actively maintained
Alternative to:
Cloudflare Web Application Firewall (WAF) logo
Cloudflare Web Application Firewall (WAF)
+10
SWAG logo

SWAG

Nginx reverse proxy with automated TLS certificates and fail2ban

3.7k
276
Last commit

LinuxServer.io SWAG is a Docker image bundling Nginx reverse proxy, ACME certificate automation (Let’s Encrypt/ZeroSSL), optional PHP, and fail2ban intrusion prevention.

GPL-3.0Actively maintained
Alternative to:
Apache HTTP Server logo
Apache HTTP Server
+9
NPMplus logo

NPMplus

Fork of Nginx Proxy Manager with HTTP/3, OIDC, and hardening

2.3k
118
Last commit

NPMplus is a Nginx Proxy Manager fork that adds HTTP/3 (QUIC), OIDC auth, stronger TLS defaults, and extra security and logging features in a web UI.

AGPL-3.0Actively maintained
Alternative to:
NGINX Management Suite logo
NGINX Management Suite
+5
UUSEC WAF logo

UUSEC WAF

Web application firewall and API security gateway (WAAP)

1.7k
170
Last commit

High-performance web application firewall and API security gateway with semantic detection, rule management, and reverse-proxy deployment for protecting websites and APIs.

BSD-2-ClauseActively maintained
Alternative to:
Cloudflare Web Application Firewall (WAF) logo
Cloudflare Web Application Firewall (WAF)
+9
Nginx Proxy Manager logo

Nginx Proxy Manager

Web UI to manage Nginx reverse proxy hosts and SSL certificates

34k
3.9k
Last commit

Nginx Proxy Manager is a web-based admin panel for managing Nginx reverse proxy hosts, redirects, streams, and Let’s Encrypt SSL certificates via Docker.

MITActively maintained
Alternative to:
NGINX Management Suite logo
NGINX Management Suite
+6