BunkerWeb is an open-source web application firewall and NGINX-based server that protects web services as a reverse proxy. Its core protections include HTTPS with automated Let's Encrypt, HTTP security headers, TLS hardening, ModSecurity with the OWASP Core Rule Set and automatic bans for suspicious behavior. Bot challenges can use cookies, JavaScript, CAPTCHA, hCaptcha, reCAPTCHA or Turnstile. It can block known malicious IPs using external blacklists and DNS-based blackhole lists. Supported deployment integrations include Docker, Docker autoconf, Swarm, Kubernetes and Linux. An optional web UI manages instances and configurations, but currently supports Docker and Linux integrations. The open-source edition is available at no cost under the AGPLv3 license. PRO pricing depends on the number of services protected; Standard has no technical support, while Enterprise includes dedicated support. Kubernetes Gateway API mode is currently beta. The documentation recommends restricting API access with an IP whitelist and optionally using an API token.
Who it is for
BunkerWeb suits teams seeking a self-hosted reverse proxy with web application firewall protections. It supports several deployment integrations, including Docker, Kubernetes and Linux.
What is good
- Includes ModSecurity with the OWASP Core Rule Set.
- Bot challenges offer several methods.
- Supported integrations include Docker, Swarm and Kubernetes.
- Open-source edition is free under AGPLv3.
What to know first
- Kubernetes Gateway API mode is beta.
- Optional web UI supports only Docker and Linux integrations.
- PRO Standard includes no technical support.
Verdict
BunkerWeb combines reverse-proxy operation with web application and bot protections. Check the beta status of Kubernetes Gateway API mode and the web UI's integration limits before choosing a deployment.
BunkerWeb plans and pricing
All plansCompared on reverse proxy software
- Free plan
- Yes
- Rate limiting
- Yes




