NetGoat
Self-hostable reverse proxy and traffic manager with WAF features
890 stars 47 forks last commit first released AGPL-3.0
Actively maintained
Last commit 29 Jul 2026.

NetGoat is a self-hostable reverse proxy engine and traffic manager designed to provide Cloudflare-like controls for routing, security, and performance. It aims to help homelabs and teams manage inbound web traffic with an integrated UI and rule-based behavior.
Key Features
- Reverse proxy for HTTP traffic, including WebSocket support
- TLS termination with automated certificate handling
- WAF-style request filtering and anti-abuse protections
- Rate limiting and request queuing to protect APIs and apps
- Load balancing and failover for multi-node routing
- Per-domain configuration with wildcard/regex support
- Dynamic rules engine for custom routing and filtering logic
- Metrics dashboard for traffic and error visibility
- Optional integration targeting Cloudflare workflows (such as tunnels)
Use Cases
- Fronting multiple self-hosted services with a single security and routing layer
- Adding rate limiting and basic WAF protections to APIs and web apps
- Managing multi-service homelab ingress with per-domain policies and monitoring
Limitations and Considerations
- Project is explicitly work-in-progress; features and stability may change significantly
- Some advertised capabilities may be incomplete depending on the current release state
NetGoat is best suited for users who want a centralized, UI-driven reverse proxy with security-focused controls and extensibility. As it matures, it can serve as a flexible edge layer for both homelab and small-team deployments.
Categories:
Tags:
Tech Stack:
Similar to NetGoat

Wiredoor
Ingress-as-a-service to expose private services via WireGuard and NGINX
Self-hosted ingress platform that exposes internal HTTP/TCP services to the internet through reverse WireGuard tunnels, with NGINX routing and automatic TLS certificates.

BunkerWeb
Open-source web application firewall and reverse proxy
BunkerWeb is an open-source WAF and NGINX-based reverse proxy to protect web apps and APIs with HTTPS automation, security policies, and extensible plugins.
SWAG
Nginx reverse proxy with automated TLS certificates and fail2ban
LinuxServer.io SWAG is a Docker image bundling Nginx reverse proxy, ACME certificate automation (Let’s Encrypt/ZeroSSL), optional PHP, and fail2ban intrusion prevention.

NPMplus
Fork of Nginx Proxy Manager with HTTP/3, OIDC, and hardening
NPMplus is a Nginx Proxy Manager fork that adds HTTP/3 (QUIC), OIDC auth, stronger TLS defaults, and extra security and logging features in a web UI.

UUSEC WAF
Web application firewall and API security gateway (WAAP)
High-performance web application firewall and API security gateway with semantic detection, rule management, and reverse-proxy deployment for protecting websites and APIs.

Nginx Proxy Manager
Web UI to manage Nginx reverse proxy hosts and SSL certificates
Nginx Proxy Manager is a web-based admin panel for managing Nginx reverse proxy hosts, redirects, streams, and Let’s Encrypt SSL certificates via Docker.



