Commit Graph
3 Commits
Author SHA1 Message Date
sneak 0d81aa20df Deploy model: apps build FROM the smallwebwaf image (closes #12)
SPEC.md and README.md now describe the recommended deploy: an app's
Dockerfile builds FROM the smallwebwaf image, and runit, started by
runsvinit, runs smallwebwaf on :8080 in front of the app on
127.0.0.1:8081, with no setting required. They cover which user each
process runs as, what happens when either exits, the health check, the
ports, the state directory and its volume, the app's trusted proxies,
the new defaults and upaas needing no change, with an example app
Dockerfile in place of the docker-compose examples. Every setting
carries the SWWAF_ prefix, and the spec no longer calls smallwebwaf a
sidecar.

Model: opus-5-5
2026-09-28 23:34:48 +00:00
clawbot 789895782e Rewrite SPEC and README to sneak's rulings and internet-ready defaults (closes #6)
SPEC.md and README.md now state the resolutions of the old questions section and sneak's later requirements: seven-day bans for clear signs of attack and short, tripling bans for broken limits; state files that follow memory and take in edits while running; ban notes and per-client history; size and time limits in both directions; country deny and allow-only lists; GeoJS as the default lookup source; one listener for everything. The defaults are chosen so that a sidecar with only UPSTREAM_URL set protects an app on the open internet; the Core Rule Set reads no request bodies by default. Choices made where his words left a gap are listed in the PR. Gitea requests the defaults may still refuse are collected in a follow-up issue.

Model: opus-5-5
2026-09-29 00:53:01 +02:00
sneak a0d2c21346 Add README, SPEC and tool evaluation, closes #1
Initial documents: what smallwebwaf is and why, the proposed feature list, the design spec with the rule file format and the open design questions, and the survey of existing tools.

Model: fable-5-1
2026-09-21 07:42:45 +00:00