coraza-traefik
coraza
coraza-traefik | coraza | |
---|---|---|
1 | 7 | |
18 | 1,843 | |
- | 4.7% | |
1.8 | 8.7 | |
over 2 years ago | 5 days ago | |
Go | Go | |
- | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
coraza-traefik
coraza
- Coraza: Coraza WAF is a Golang modsecurity compatible web application firewall
-
WAF with reverse proxy
Is there a reason no one hasn't made a Docker template for OWASP Coraza (https://github.com/corazawaf/coraza) or ModSecurity (https://github.com/SpiderLabs/ModSecurity) for the use of a reverse proxy?
- Traefik WAF Plugin with OWASP/Modsecurity
-
Go: Yaml DB
Interesting work, I was going to implement https://github.com/antchfx/jsonquery for github.com/jptosso/coraza-waf but your idea seems quite useful. I would remove logrus, as logs should be created by the implementation, not the library (or at least that's what a think)
-
Protect your web applications with Coraza library
Coraza WAF is a golang web application firewall library that has reached a stable point (v1 is releasing tomorow). https://github.com/jptosso/coraza-waf
-
Golang Web Application Firewall
You have a point there, maybe releasing a v1.0 is not that crazy at all, it's much easier to type import "github.com/jptosso/coraza-waf/v1" indeed
What are some alternatives?
traefik-real-ip - When traefik is deployed behind a load balancer, it should get the real IP from the X-Forwarded-For or Cf-Connecting-Ip (if from Cloudflare) header.
traefik-modsecurity-plugin - Traefik plugin to proxy requests to owasp/modsecurity-crs:apache container
souin - An HTTP cache system, RFC compliant, compatible with @tyktechnologies, @traefik, @caddyserver, @go-chi, @bnkamalesh, @beego, @devfeel, @labstack, @gofiber, @go-goyave, @go-kratos, @gin-gonic, @roadrunner-server, @zalando, @zeromicro, @nginx and @apache
ModSecurity - ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analysis.
ModSecurity-nginx - ModSecurity v3 Nginx Connector
traefik-ondemand-plugin - Traefik plugin to scale containers on demand
coraza-caddy - OWASP Coraza middleware for Caddy. It provides Web Application Firewall capabilities
pluginproviderdemo - This repository includes an example provider plugin, for you to use as a reference for developing your own plugins
lua-resty-waf - High-performance WAF built on the OpenResty stack
coraza-gin - Coraza WAF Gin-gonic middleware
ACL - A simple but powerful Access Control List manager