What is it?
BunkerWeb is an open source web application firewall (WAF) published by Bunkerity, a French company. It is an NGINX server you put in front of your apps as a reverse proxy: every request goes through ModSecurity and the OWASP Core Rule Set (v4 by default), then blocklists and rate limits, before it reaches the service. BunkerWeb installs as a Linux package (Debian, Ubuntu, Fedora, RHEL and its rebuilds), as Docker containers or on Kubernetes. Everything is driven by settings such as SERVER_NAME, USE_ANTIBOT or AUTO_LETS_ENCRYPT, passed as environment variables, Docker labels or Ingress annotations, or edited in a web UI.
CrowdSec starts from logs: it spots malicious behavior there and has bouncers block the offending IPs. BunkerWeb can be one of those bouncers, and its all-in-one image ships a CrowdSec agent, off by default. open-appsec plugs into an existing NGINX and replaces signatures with a model that learns from your traffic. BunkerWeb takes the reverse proxy's place and sticks with CRS rules, false positive tuning included.
The open source WAF comparison sets this rule-based blocking against CrowdSec's shared reputation and open-appsec's trained models.
Why is it interesting?
- Protection on from the first start: ModSecurity with the CRS, per-IP request and connection limits, and automatic bans for clients that pile up HTTP errors. In
detectmode it logs without blocking while you track down false positives. - Eight bot challenges: cookie, JavaScript, built-in captcha, reCAPTCHA, hCaptcha, Turnstile, mCaptcha and Cap.js, chosen per service.
- Configuration that follows your containers: the autoconf service watches Docker or Kubernetes and reconfigures BunkerWeb when a container or an Ingress appears, without recreating the container. On Kubernetes it is the Ingress controller, with an official Helm chart.
- Many sites on one instance: in multisite mode each app keeps its own settings, prefixed with its server name (
www.example.com_USE_ANTIBOT=captcha). - Official plugins: ClamAV or VirusTotal to scan uploaded files, Coraza in place of ModSecurity, alerts to Discord, Slack or a webhook.
Good to know
The defaults are strict. Each IP gets 2 requests per second per URL, and a client that receives 10 responses with status 400, 401, 403, 404, 405, 429 or 444 within 60 seconds is banned for 24 hours. The README "strongly recommends" tuning these values.
Several components run together. Outside the all-in-one image you need at least the NGINX instance and the scheduler, which stores the configuration in a database and renders it. SQLite is the default; MariaDB, MySQL and PostgreSQL are supported. On Kubernetes, several instances require a shared Redis or Valkey. The docs give no memory figures for self-hosting.
Instances talk to Bunkerity out of the box. BunkerNet, on by default, registers the instance with api.bunkerweb.io, reports blocked IPs anonymously and downloads the shared list in return. USE_BUNKERNET=no turns it off.
Authentication and metrics are PRO features. The docs flag nineteen PRO modules, among them OpenID Connect, SAML and LDAP SSO in front of your apps, the Prometheus exporter, anti-DDoS and multi-user management in the web UI. The free version can hand login off to an external service through REVERSE_PROXY_AUTH_REQUEST, built on NGINX's auth_request, which Authelia supports. The pricing page lists €49 a month for Shield (community support) and €149 for Fortress (priority support), with a 30-day trial, and the license needs outbound access to api.bunkerweb.io. The free version is AGPL-3.0: anyone who runs a modified version as a network service must publish its source.
Swarm is deprecated. The Swarm integration will be removed in a future release, and the docs point to Kubernetes instead. Gateway API mode on Kubernetes is in beta.
Roughly one stable release a month. The repository dates back to 2019. The latest stable release is 1.6.15, from September 21, 2026, and 1.6.16 is at its fourth release candidate (October 6, 2026). Nine stable releases have shipped since January 2026.
