Aegis is an open-source, high-performance Web Application Firewall and edge reverse proxy that inspects HTTP/HTTPS traffic in real time to block attacks, malicious bots, and abusive surges before they reach backend services. It integrates the OWASP Core Rule Set to defend against Top 10 threats (SQLi, XSS, RCE, SSRF, path traversal), uses intelligent anomaly scoring to reduce false positives, and supports custom rules and whitelisting. Traffic-control features include rate limiting, anti-scraping, IP access control, geo-blocking, and connection thresholds. HTTP hardening enforces allowed methods, request and payload size limits, file-upload protection, automated security headers, and infrastructure-cloaking. TLS is automated via Let's Encrypt with enterprise certificate support and strict TLS 1.2/1.3 configuration. The proxy supports HTTP/1.1, HTTP/2, and HTTP/3 with dynamic route management, load balancing, active health checks, and a design targeted for sub-millisecond inspection overhead.
Operationally, Aegis provides an embedded web admin console and control API for zero-downtime policy updates, real-time analytics, threat logs, and MFA for admin access. Deployment options include a one-line universal installer, a Docker Compose stack that pairs Aegis with PostgreSQL (control DB) and ClickHouse (analytics), precompiled standalone binaries for Linux and Windows, or building from source for contributors. The distribution bundles default configurations and rulesets, supports wildcard SNI and enterprise cert workflows, and emphasizes dynamic, production-ready edge security and observability.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.