|
|
|
@@ -1,14 +1,15 @@
|
|
|
|
|
# smallwebwaf
|
|
|
|
|
|
|
|
|
|
`smallwebwaf` is a simple, fast, logging web application firewall, written in Go
|
|
|
|
|
by [@sneak](https://sneak.berlin), for people who host their own services. It
|
|
|
|
|
runs inside the container of the one application it protects, between your
|
|
|
|
|
reverse proxy (traefik) and the app: the app's Dockerfile builds `FROM` the
|
|
|
|
|
`smallwebwaf` image, traefik sends the app's requests to `smallwebwaf` on port
|
|
|
|
|
8080, and `smallwebwaf` passes them on to the app on `127.0.0.1:8081`. It needs
|
|
|
|
|
no setting, and protects the app from the first request with defaults chosen for
|
|
|
|
|
a service on the open internet. It keeps its state in memory and in JSON files
|
|
|
|
|
you can read and edit, and writes a detailed JSON log line for every request.
|
|
|
|
|
`smallwebwaf` is a simple, fast, logging web application firewall, MIT-licensed
|
|
|
|
|
and written in Go by [@sneak](https://sneak.berlin), for people who host their
|
|
|
|
|
own services. It runs inside the container of the one application it protects,
|
|
|
|
|
between your reverse proxy (traefik) and the app: the app's Dockerfile builds
|
|
|
|
|
`FROM` the `smallwebwaf` image, traefik sends the app's requests to
|
|
|
|
|
`smallwebwaf` on port 8080, and `smallwebwaf` passes them on to the app on
|
|
|
|
|
`127.0.0.1:8081`. It needs no setting, and protects the app from the first
|
|
|
|
|
request with defaults chosen for a service on the open internet. It keeps its
|
|
|
|
|
state in memory and in JSON files you can read and edit, and writes a detailed
|
|
|
|
|
JSON log line for every request.
|
|
|
|
|
|
|
|
|
|
Status: the first milestone is built
|
|
|
|
|
(https://git.eeqj.de/sneak/smallwebwaf/issues/13). `smallwebwaf` passes each
|
|
|
|
@@ -431,7 +432,6 @@ so that they run in minimal containers.
|
|
|
|
|
|
|
|
|
|
- Milestone 2: rate limits per client, the country lists and the image an app
|
|
|
|
|
builds on (https://git.eeqj.de/sneak/smallwebwaf/issues/14).
|
|
|
|
|
- The licence (https://git.eeqj.de/sneak/smallwebwaf/issues/15).
|
|
|
|
|
- The rest of the design, in the order of the build order in
|
|
|
|
|
[`SPEC.md`](SPEC.md).
|
|
|
|
|
|
|
|
|
@@ -442,6 +442,10 @@ so that they run in minimal containers.
|
|
|
|
|
and misses, and why none was adopted.
|
|
|
|
|
- [`REPO_POLICIES.md`](REPO_POLICIES.md): the policies this repository follows.
|
|
|
|
|
|
|
|
|
|
## License
|
|
|
|
|
|
|
|
|
|
MIT. See [`LICENSE`](LICENSE).
|
|
|
|
|
|
|
|
|
|
## Author
|
|
|
|
|
|
|
|
|
|
[@sneak](https://sneak.berlin)
|
|
|
|
|