nowfound

Alternatives

Products that do what BunkerWeb does

An open-source, cloud-native WAF you fully control

  1. 1BT
  2. 2BT
  3. 3NW
  4. 4

    Open source alternative to AWS

    2024 · ubicloud.com

  5. 5OS

    I've been working on this for some time now, starting with vm2, then deno-core for 2 years, and recently rewrote it on rusty_v8 with Claude's help. OpenWorkers lets you run untrusted JS in V8 isolates on your own infrastructure. Same DX as Cloudflare Workers, no vendor lock-in. What works today: fetch, KV, Postgres bindings, S3/R2, cron scheduling, crypto.subtle. Self-hosting is a single docker-compose file + Postgres. Would love feedback on the architecture and what feature you'd want next.

    Jan 2026 · openworkers.com

  6. 6
    Golf378

    The enterprise firewall for MCP providers

    Nov 2025

  7. 7BM
  8. 8SA

    Hi HN, I’ve been working on Shibuya, a next-generation Web Application Firewall (WAF) built from the ground up in Rust. I wanted to build a WAF that didn't just rely on legacy regex signatures but could understand intent and perform at line-rate using modern kernel features. What makes Shibuya different: Multi-Layer Pipeline: It integrates a high-performance proxy (built on Pingora) with rate limiting, bot detection, and threat intelligence. eBPF Kernel Filtering: For volumetric attacks, Shibuya can drop malicious packets at the kernel level using XDP before they consume userspace resources.…

    Feb 2026 · ghostklan.com

  9. 9M3
  10. 10KA
  11. 11

    Cloud firewalls from Digital Ocean

    2017

  12. 12PV

    Hey HN, My name is Jack Naglieri. I’m the founder of Panther Labs - an SF-based cybersecurity startup. Prior to Panther, I was an engineering manager at Airbnb. Before that a security engineer/analyst/forensic analyst. Today, I’m excited to announce Panther v1.0, an open source, cloud-native SIEM: http://github.com/panther-labs/panther Teams can use Panther as an alternative to traditional SIEMs like Splunk. Panther is the culmination of our team’s experience building security tools at scale, including StreamAlert at Airbnb and critical internal monitoring…

    2020

  13. 13TR
  14. 14

    Open-source API gateway with built-in WAF — no code changes

    Apr 2026 · backport.in

  15. 15WM

    Howdy folk, I've been building this project as both a side project and my job for a little while now. The rationale behind it is while wireguard is a fantastic protocol cryptographically it leaves a lot to be desired when it comes to enrollment and end user device security. Obviously instead of using an off the shelf solution like tailscale, I decided to reinvent the wheel which has honestly been quite fun with learning about eBPF, and recently clustering and HA with etcd! The most recent version (in the docker container) contains about 6 months of very new work bringing it all from sqlite3…

    2024 · github.com

  16. 16MN

    This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers. Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking. It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability. I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that…

    Feb 2026 · github.com

  17. 17PA
  18. 18LD

    Hi HN! I'm Jarek, and I've built this tool that allows publishing .local domains on the local network using mDNS. It also has a reverse proxy that handles HTTPS termination and port forwarding. I'm working on adding more features, like an index page with all available domains or allowing proxy redirects, so you could redirect from HTTP to HTTPS. Let me know if you have any questions or feedback!

    2023 · localcan.com

  19. 19

    Fully managed DDoS protection

    2021

  20. 20SO

    Hello HN! I'm an engineer at Splitgraph and recently started learning Rust so I could make my first contribution to Seafowl [0], an early stage analytical database. Along the way I figured out a database hosting hack on GCP and wanted to share it with HN. It's a way to achieve "true" scale to zero database hosting that could be useful for certain side projects or spiky traffic situations. A recurring problem I've faced with side projects is the need for Postgres, but no desire to deploy or maintain new instances. So when I learned GCP's "always free" tier includes serverless [1] I got…

    2023 · github.com

  21. 21OW
  22. 22

    Website protection & CMS protection

    Nov 2025

  23. 23
    WGE5

    A high-performance web application firewall library(C++)

    Nov 2025

  24. 24IB

    BoringSSL and nghttp2. Matches JA3N, JA4, and JA4_R fingerprints. Supports HTTP/2, async/await, and works with Cloudflare-protected sites. Not trying to compete with curl_cffi - just a learning project that turned into something functional.

    Nov 2025 · github.com

Ranked by how close each launch is in meaning, then by votes. Refine with a description →