BunkerWeb
authelia
BunkerWeb | authelia | |
---|---|---|
16 | 174 | |
3,485 | 19,578 | |
2.1% | 1.8% | |
9.9 | 9.9 | |
1 day ago | 5 days ago | |
Lua | Go | |
GNU Affero General Public License v3.0 | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
BunkerWeb
- BunkerWeb: Nginx-based open-source Web Application Firewall (WAF)
-
How do you protect your network before exposing 80/443 to the world?
Keep in mind that integrating a WAF can render certain apps not working if the security configuration is set too paranoid. There are a lot of examples for apps that might be affected, though.
-
Nginx Proxy Manager
Its documentation is nice as well. You can also find them on Discord and the GitHub repo is also pretty clean and have many example configurations there.
-
Security - Use VPS as reverse proxy only or actually host apps in it?
This also effectively allows your killswitch to be Nginx on the VPS while still allowing local network traffic at home. You can take it a step further and geoblock countries and more with https://github.com/bunkerity/bunkerweb.
-
NGINX or Caddy?
I know you asked about Nginx vs Caddy but to throw another one into the mix have a look at BunkerWeb. I only started using it within the last couple of months but it's based on Nginx with a tonne of usability and security improvements. I now use BunkerWeb to expose services externally and Traefik internally.
-
[Help] Simple static website in multi-site setup.
Creating a new discussion here doesn't seem to be an option (doesn't allow me to do so) so I came here.
- bunkerweb - Make your web services secure by default
-
Rebuiding my entire server - Looking for advises to start on a right foot
There's also a security optimized NGINX image called BunkerWeb. It has a WAF builtin and an optional web interface.
-
Structure of my rebuilt HomeServer with Podman
Right now I'm doing a similar setup but I want to use NGINX with integrated WAF.
-
Pre-compiled Modsecurity for Nginx in Centos
Bunkerised nginx comes me in mind here https://github.com/bunkerity/bunkerized-nginx
authelia
-
Keycloak SSO with Docker Compose and Nginx
It's me and two others though I'm definitely the most active. We put a lot of effort into security best practices and one of my co-developers is currently reviewing the 4.38.0 release. It's a fairly major release with a lot of important code paths that have been improved for the future.
Our official docs can be found at https://www.authelia.com and you can find docs for a particular PR in the relevant PR. We've also linked the pre-release docs in the pre-release discussions which can be found here: https://github.com/authelia/authelia/discussions/categories/...
-
Protecting WebUI on public IP?
I use NGINX proxy with Authelia in between. Authelia blocks and blacklists faulty logins.
-
Why would anyone need AD/AAD when you can manage devices through Saltstack?
https://github.com/saltstack/salt https://github.com/chocolatey/choco https://github.com/nextcloud https://github.com/authelia/authelia https://github.com/grafana/grafana
- Give this project some luv: Single Sign-On Multi-Factor portal for web apps
-
HAProxy with Forward Auth to Authentik
If you are using HAProxy on PfSense/OPNSense, see my issue https://github.com/authelia/authelia/issues/2696
- Keycloak – Open-Source Identity and Access Management Interview
-
LDAP or AD for selfhosted
https://github.com/lldap/lldap is a very simple and lightweight LDAP solution. Works flawless with https://www.authelia.com/
-
Authelia/SSO With Caddy In Docker Compose?
Ah yeah, so I guess it's been a while since I tried and I forgot where I got stuck last time. Authelia's config.yml is absolutely massive and I'm not sure which section of their guide I should be following. In The Docker Compose section, there's "Unbundled", "Lite", and "Local". I think I want to be running the "lite" bundle, but their example compose file has a ton of Traefik stuff in it. I know I wouldn't keep the Traefik services, but do I need either secure or public?
-
How do you secure your webpages that have no protection?
Authelia supports SSO. If you are behind a reverse proxy it’s quite straightforward to integrate.
-
GitLab behind Authelia
This should probably also be mentioned in the documentation so maybe consider mentioning this on their discussion page.
What are some alternatives?
Nginx Proxy Manager - Docker container for managing Nginx proxy hosts with a simple, powerful interface
authentik - The authentication glue you need.
miniProxy
Keycloak - Open Source Identity and Access Management For Modern Applications and Services
traefik-modsecurity-plugin - Traefik plugin to proxy requests to owasp/modsecurity-crs:apache container
oauth2 - Go OAuth2
traefik - The Cloud Native Application Proxy
oauth2-proxy - A reverse proxy that provides authentication with Google, Azure, OpenID Connect and many more identity providers.
socks5-proxy-server - SOCKS5 proxy server
nginx-proxy - Automated nginx proxy for Docker containers using docker-gen [Moved to: https://github.com/nginx-proxy/nginx-proxy]
dex - OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors