<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Lia</title>
    <description>The latest articles on DEV Community by Lia (@lialiago).</description>
    <link>https://dev.to/lialiago</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2050794%2F3814506f-596e-4892-bf72-747df3d307fe.jpeg</url>
      <title>DEV Community: Lia</title>
      <link>https://dev.to/lialiago</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/lialiago"/>
    <language>en</language>
    <item>
      <title>Self-Hosted WAF with a Low False Positive Rate: Why It Matters</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Wed, 30 Sep 2026 03:25:48 +0000</pubDate>
      <link>https://dev.to/lialiago/self-hosted-waf-with-a-low-false-positive-rate-why-it-matters-2ob</link>
      <guid>https://dev.to/lialiago/self-hosted-waf-with-a-low-false-positive-rate-why-it-matters-2ob</guid>
      <description>&lt;h1&gt;
  
  
  Self-Hosted WAF with a Low False Positive Rate: Why It Matters
&lt;/h1&gt;

&lt;p&gt;When you shop for a WAF, the headline number everyone shows is detection rate — how much attack traffic it catches. That's important, but it's only half the story. The other half is the &lt;strong&gt;false positive rate (FPR)&lt;/strong&gt;: how often the WAF wrongly flags legitimate traffic as an attack. A WAF that blocks 100% of attacks but also blocks 20% of your real users is worse than no WAF at all.&lt;/p&gt;

&lt;p&gt;If you self-host, a low-FPR WAF protects your traffic without becoming a daily source of "why is the site down?" tickets. Here's what to look for.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a false positive actually costs
&lt;/h2&gt;

&lt;p&gt;A false positive is a real, innocent request — a customer's login, a partner's API call, a search query with an odd character — that the WAF drops because it looked malicious. The consequences:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Lost conversions&lt;/strong&gt; — blocked customers don't retry, they leave.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Broken integrations&lt;/strong&gt; — a partner API call rejected mid-flow.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Alert fatigue&lt;/strong&gt; — your team starts ignoring the WAF because it "always complains."&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;High FPR pushes teams to loosen rules until the WAF stops helping. Low FPR means you can keep protection tight without breaking the business.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why some WAFs trip on false positives
&lt;/h2&gt;

&lt;p&gt;Traditional signature-based WAFs match requests against a list of known attack patterns. That's brittle: an unusual-but-valid input — a SQL-looking string in a search box, an encoded parameter — can trip a rule that was meant for something else. The more rules you stack to catch attacks, the more innocent traffic you risk catching too.&lt;/p&gt;

&lt;h2&gt;
  
  
  How a semantic engine lowers the rate
&lt;/h2&gt;

&lt;p&gt;A semantic-detection engine (the approach SafeLine uses) doesn't just pattern-match. It analyzes the &lt;em&gt;intent&lt;/em&gt; of a request — whether it's actually trying to exploit something — rather than whether it contains a suspicious-looking substring. Valid-but-odd requests pass; genuinely malicious ones are blocked. That distinction is what keeps the false positive rate low.&lt;/p&gt;

&lt;p&gt;In SafeLine's published benchmark (its BlazeHTTP test against tens of thousands of attack payloads), the Community Edition posted a &lt;strong&gt;0.07% false positive rate&lt;/strong&gt; while still detecting the large majority of attacks — markedly lower than the double-digit FPR seen in some signature-rule configurations of traditional WAFs in the same test. The point isn't the exact figure; it's that a semantic approach is designed to keep legitimate traffic flowing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to check before you commit
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Request intent, not just signatures&lt;/strong&gt; — ask whether the engine understands the request or just matches strings.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Tunable thresholds&lt;/strong&gt; — you should be able to tighten or loosen without rewriting rules by hand.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Transparent logs&lt;/strong&gt; — when something is blocked, you need to see why, fast.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Self-hosted fit&lt;/strong&gt; — run it where your traffic already flows, with no per-request billing.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Deploying it
&lt;/h2&gt;

&lt;p&gt;Bring up SafeLine as a reverse proxy in front of your app:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add your site, point its upstream at your app, and let the detection engine filter traffic. Review the logs for a day of real traffic, allowlist any legitimate patterns that surface, and you have tight protection with minimal noise.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is a low false positive rate the same as high detection?
&lt;/h3&gt;

&lt;p&gt;No — they're independent. A WAF can be great at one and poor at the other. You want both: catch the attacks &lt;em&gt;and&lt;/em&gt; let real traffic through.&lt;/p&gt;

&lt;h3&gt;
  
  
  Should I trust a vendor's benchmark number?
&lt;/h3&gt;

&lt;p&gt;Treat published benchmarks as directional, not gospel — your traffic is the real test. Run the WAF in front of live traffic and watch the logs before drawing conclusions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will a semantic engine ever false-positive?
&lt;/h3&gt;

&lt;p&gt;Any filter can, on sufficiently unusual input. The advantage is far fewer of them, and clear logs make the rare miss easy to spot and allowlist.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is this free to self-host?
&lt;/h3&gt;

&lt;p&gt;The Community Edition is free to run indefinitely and covers up to 10 apps at 800 QPS, with the same detection engine as the paid tiers.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — you can run tight WAF protection without flooding your team with false alarms.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>devops</category>
      <category>selfhosted</category>
    </item>
    <item>
      <title>How to Detect and Block Malicious Bots (Without Blocking Real Users)</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Wed, 30 Sep 2026 03:23:57 +0000</pubDate>
      <link>https://dev.to/lialiago/how-to-detect-and-block-malicious-bots-without-blocking-real-users-14fc</link>
      <guid>https://dev.to/lialiago/how-to-detect-and-block-malicious-bots-without-blocking-real-users-14fc</guid>
      <description>&lt;h1&gt;
  
  
  How to Detect and Block Malicious Bots (Without Blocking Real Users)
&lt;/h1&gt;

&lt;p&gt;Not all bots are bad. Search engines crawl your site to index it; monitoring and webhooks call your APIs legitimately. The problem is the other kind — scrapers, credential stuffers, spam bots, and DDoS clients — that abuse your resources or probe for weaknesses. The trick isn't blocking bots wholesale; it's telling the good from the bad and acting on the difference.&lt;/p&gt;

&lt;p&gt;Here's a practical approach, and where a self-hosted WAF like SafeLine fits.&lt;/p&gt;

&lt;h2&gt;
  
  
  First, recognize the traffic
&lt;/h2&gt;

&lt;p&gt;Bots reveal themselves through patterns a human never produces:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Volume and rate&lt;/strong&gt; — hundreds of requests from one source far faster than a person can click.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Repetitive paths&lt;/strong&gt; — the same endpoint hammered in a loop (login, search, checkout).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Thin or spoofed headers&lt;/strong&gt; — missing &lt;code&gt;User-Agent&lt;/code&gt;, or a fingerprint shared across thousands of requests.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Behavioral tells&lt;/strong&gt; — same sequence, same timing, no variation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Legitimate bots (Googlebot, Bingbot, status checkers) usually identify themselves and behave predictably. The noisy, evasive ones are what you want to stop.&lt;/p&gt;

&lt;h2&gt;
  
  
  A layered response
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Allowlist the good bots.&lt;/strong&gt; If you want search engines to index you, let known crawlers through by identity rather than treating all automation as hostile.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limit the rest.&lt;/strong&gt; Cap requests per IP and per path so one client can't monopolize an endpoint.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Challenge the suspicious.&lt;/strong&gt; Force a CAPTCHA or temporary block on clients that look automated but you're not certain about.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Block the known-bad.&lt;/strong&gt; Drop traffic from sources with clear abuse signatures.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Where SafeLine fits
&lt;/h2&gt;

&lt;p&gt;SafeLine is a self-hosted WAF that runs in reverse-proxy mode in front of your app, so every request passes through it first. For bot mitigation:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Bot management&lt;/strong&gt; distinguishes automated clients from real users using behavioral and request analysis, so it can throttle or block the abusive ones while letting people through.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limiting&lt;/strong&gt; can be applied per path — ideal for login, search, and API endpoints that bots love to hammer.&lt;/li&gt;
&lt;li&gt;Because it's &lt;strong&gt;self-hosted and free to run&lt;/strong&gt; (Community Edition covers up to 10 apps at 800 QPS), you get bot protection without adding a per-request vendor bill.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal is surgical: stop the abuse, keep the legitimate traffic — including the good bots you actually want.&lt;/p&gt;

&lt;h2&gt;
  
  
  Putting it in front of your traffic
&lt;/h2&gt;

&lt;p&gt;Deploy SafeLine as the proxy in front of your service:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add your site and point its upstream at your app. Enable bot mitigation, set rate limits on your highest-traffic paths, and allowlist the crawlers you trust. From there, malicious bots get throttled or blocked at the edge while real users and legitimate bots flow through.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Won't blocking bots hurt my SEO?
&lt;/h3&gt;

&lt;p&gt;Only if you block the good ones. Allowlist search-engine crawlers by identity and they'll index normally; you're targeting abusive automation, not legitimate crawlers.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can a WAF tell a bot from a human reliably?
&lt;/h3&gt;

&lt;p&gt;It uses behavioral and request signals, not a perfect test. Rate limiting and challenges handle the uncertain cases; outright abuse is blocked outright.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need to write bot-detection rules myself?
&lt;/h3&gt;

&lt;p&gt;No. SafeLine's bot management works out of the box; you tune thresholds and allowlists rather than hand-authoring detection logic.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is this free to self-host?
&lt;/h3&gt;

&lt;p&gt;Yes — the Community Edition is free to run indefinitely and covers up to 10 apps at 800 QPS.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — your traffic now has bot filtering and rate limiting at the edge.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>programming</category>
      <category>security</category>
      <category>cybersecurity</category>
      <category>devops</category>
    </item>
    <item>
      <title>How to Prevent XSS with a WAF: Filter the Payload Before It Lands</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Tue, 29 Sep 2026 03:12:36 +0000</pubDate>
      <link>https://dev.to/lialiago/how-to-prevent-xss-with-a-waf-filter-the-payload-before-it-lands-212h</link>
      <guid>https://dev.to/lialiago/how-to-prevent-xss-with-a-waf-filter-the-payload-before-it-lands-212h</guid>
      <description>&lt;h1&gt;
  
  
  How to Prevent XSS with a WAF: Filter the Payload Before It Lands
&lt;/h1&gt;

&lt;p&gt;Cross-site scripting (XSS) is one of the oldest web vulnerabilities — and still one of the most common. It lets an attacker run script in your users' browsers: stealing sessions, defacing pages, or pivoting into deeper access. The good news is that XSS is also highly preventable, and a WAF is a strong first layer.&lt;/p&gt;

&lt;p&gt;This guide covers where a WAF fits in XSS defense, and what your application still needs to do.&lt;/p&gt;

&lt;h2&gt;
  
  
  What XSS is, quickly
&lt;/h2&gt;

&lt;p&gt;XSS happens when untrusted input is reflected into a page and executed as script. The classic case: a comment field that renders user text without escaping, so &lt;code&gt;&amp;lt;script&amp;gt;...&amp;lt;/script&amp;gt;&lt;/code&gt; runs in every visitor's browser. There are also stored and DOM-based variants, but the core problem is the same — untrusted data treated as code.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where a WAF helps
&lt;/h2&gt;

&lt;p&gt;A WAF sits in front of your app and inspects incoming requests. For XSS, that means it can &lt;strong&gt;block malicious payloads in the request&lt;/strong&gt; — the &lt;code&gt;&amp;lt;script&amp;gt;&lt;/code&gt; tags, event handlers, and obfuscated encodings — before they ever reach your application. That stops a large share of opportunistic, automated XSS attempts cold.&lt;/p&gt;

&lt;p&gt;SafeLine, a self-hosted WAF, does this with a &lt;strong&gt;semantic detection engine&lt;/strong&gt; that analyzes request content rather than matching a static signature list. It catches XSS patterns in parameters and bodies — including the kinds of encoding tricks attackers use to slip past naive filters — and drops the request at the edge.&lt;/p&gt;

&lt;p&gt;A WAF is especially valuable as a safety net: even if a new input path ships without perfect escaping, the WAF catches the payload on the way in.&lt;/p&gt;

&lt;h2&gt;
  
  
  But a WAF is one layer, not the whole story
&lt;/h2&gt;

&lt;p&gt;XSS defense is layered, and the application side matters just as much:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Output encoding / escaping&lt;/strong&gt; — encode data for the context it's rendered in (HTML, attribute, JS, URL). This is the primary control.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Content-Security-Policy (CSP)&lt;/strong&gt; — restrict which scripts can execute, drastically limiting the blast radius of any XSS that slips through.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Input validation&lt;/strong&gt; — reject or sanitize unexpected input at the boundary.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;HttpOnly + Secure cookies&lt;/strong&gt; — make session cookies unreadable to script, so even a successful XSS can't easily steal a session.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Framework protections&lt;/strong&gt; — most modern frameworks auto-escape; keep them on and avoid &lt;code&gt;dangerouslySetInnerHTML&lt;/code&gt;-style escapes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Think of the WAF as the perimeter and the app-side controls as the inner wall. Both should be in place.&lt;/p&gt;

&lt;h2&gt;
  
  
  Deploying the WAF layer
&lt;/h2&gt;

&lt;p&gt;Bring up SafeLine as a reverse proxy in front of your app:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add your site and point its upstream at your app. With request filtering enabled, XSS payloads are blocked at the edge. Pair that with CSP and output encoding in your code, and XSS becomes a solved class of problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does a WAF fully prevent XSS on its own?
&lt;/h3&gt;

&lt;p&gt;It blocks the majority of automated and known payloads, but it shouldn't be your only control. CSP and output encoding are still essential.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will XSS filtering break legitimate form input?
&lt;/h3&gt;

&lt;p&gt;Normal text passes through; only payloads that match attack patterns are blocked. Sanity-check your real forms after enabling, as you would with any new filter.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is SafeLine's detection signature-based?
&lt;/h3&gt;

&lt;p&gt;No — it uses a semantic engine that evaluates request intent, which catches obfuscated or encoded payloads that simple pattern lists miss.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need to change app code to add the WAF?
&lt;/h3&gt;

&lt;p&gt;No. It runs in front of your app as a proxy, so the filtering is infrastructure, not application logic.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — your app now has a request-filtering layer against XSS at the edge.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>tutorial</category>
      <category>devops</category>
    </item>
    <item>
      <title>Self-Hosted API Protection: How to Put a WAF in Front of Your API</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Tue, 29 Sep 2026 03:10:27 +0000</pubDate>
      <link>https://dev.to/lialiago/self-hosted-api-protection-how-to-put-a-waf-in-front-of-your-api-3nf7</link>
      <guid>https://dev.to/lialiago/self-hosted-api-protection-how-to-put-a-waf-in-front-of-your-api-3nf7</guid>
      <description>&lt;h1&gt;
  
  
  Self-Hosted API Protection: How to Put a WAF in Front of Your API
&lt;/h1&gt;

&lt;p&gt;APIs are where the valuable data lives — and where attackers go first. A public API endpoint is a direct door to your logic, your database, and your users' sessions. If you self-host your API, you can also self-host its first line of defense: a WAF sitting in front of it, filtering traffic before it reaches your handlers.&lt;/p&gt;

&lt;p&gt;Here's how to protect a self-hosted API with a WAF, and where SafeLine fits.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why APIs are attractive targets
&lt;/h2&gt;

&lt;p&gt;Unlike a rendered web page, an API speaks machine-to-machine — and that means requests are structured, predictable, and easy to script. Attackers go after:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Authentication endpoints&lt;/strong&gt; — credential stuffing, token abuse, brute force.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Injection in parameters&lt;/strong&gt; — SQL or command injection through query strings and JSON bodies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Abuse and scraping&lt;/strong&gt; — automated clients hammering endpoints for data or compute.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Malformed payloads&lt;/strong&gt; — probing for parser or deserialization bugs.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A WAF can't fix a broken auth scheme, but it can stop the bulk of automated abuse at the edge.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a WAF does for an API
&lt;/h2&gt;

&lt;p&gt;Placed as a reverse proxy in front of your API service, a WAF:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Inspects every request&lt;/strong&gt;, including JSON bodies and query parameters, for attack patterns.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Blocks injection and known malicious payloads&lt;/strong&gt; before they reach your code.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limits&lt;/strong&gt; per client, per key, or per path — so one abusive caller can't monopolize the API.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Manages bots&lt;/strong&gt;, separating automated tooling from legitimate integrations.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Where SafeLine fits
&lt;/h2&gt;

&lt;p&gt;SafeLine is a self-hosted WAF that runs in reverse-proxy mode, so you point your API's traffic at it and it forwards clean requests to your upstream service. For API protection specifically:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Its &lt;strong&gt;semantic detection engine&lt;/strong&gt; analyzes request content — parameters, headers, and bodies — to catch injection and malicious payloads that static rules miss.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limiting&lt;/strong&gt; can be applied per path, which is ideal for throttling login, token, or search endpoints.&lt;/li&gt;
&lt;li&gt;It's &lt;strong&gt;self-hosted and free to run&lt;/strong&gt; (Community Edition covers up to 10 apps at 800 QPS), so protecting an internal or public API doesn't add a vendor bill.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;SafeLine won't replace proper auth and input validation in your code — but it removes the flood of automated junk so your application logic only sees traffic worth handling.&lt;/p&gt;

&lt;h2&gt;
  
  
  Putting it in front of your API
&lt;/h2&gt;

&lt;p&gt;Deploy SafeLine as the proxy in front of your API service:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add a site whose upstream is your API (for example &lt;code&gt;http://127.0.0.1:8080&lt;/code&gt;). Route your API's DNS or gateway at SafeLine's listener, then set rate limits on your most-sensitive paths (auth, token refresh). From there, every request is filtered and throttled before it touches your API.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does a WAF replace API authentication?
&lt;/h3&gt;

&lt;p&gt;No. You still need solid auth and authorization in your app. A WAF stops automated abuse and injection; it doesn't decide who's allowed in.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will it break legitimate API clients?
&lt;/h3&gt;

&lt;p&gt;Rate limits are set above normal client behavior, and the detection engine targets malicious patterns — legitimate requests pass through. Test against your real client traffic when configuring.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can it inspect JSON request bodies?
&lt;/h3&gt;

&lt;p&gt;Yes — a semantic engine evaluates the request content, including structured bodies, rather than only matching URLs or headers.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is this free to self-host?
&lt;/h3&gt;

&lt;p&gt;The Community Edition is free to run indefinitely and covers up to 10 apps at 800 QPS, which is plenty for a typical API footprint.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — your API now has a filtering and rate-limiting layer in front of it.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>programming</category>
      <category>security</category>
      <category>api</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to Prevent Application-Layer DDoS Attacks on Your Web App</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Mon, 28 Sep 2026 02:25:37 +0000</pubDate>
      <link>https://dev.to/lialiago/how-to-prevent-application-layer-ddos-attacks-on-your-web-app-12m2</link>
      <guid>https://dev.to/lialiago/how-to-prevent-application-layer-ddos-attacks-on-your-web-app-12m2</guid>
      <description>&lt;h1&gt;
  
  
  How to Prevent Application-Layer DDoS Attacks on Your Web App
&lt;/h1&gt;

&lt;p&gt;Most people picture DDoS as a firehose of garbage packets aimed at a network. But the attacks that actually take down modern web apps are usually quieter: &lt;strong&gt;application-layer (L7) DDoS&lt;/strong&gt;, where the flood looks like normal traffic. It's a wave of legitimate-looking HTTP requests designed to exhaust your app, database, or upstream.&lt;/p&gt;

&lt;p&gt;Because the requests aren't obviously malicious, a plain firewall can't tell them apart from real users. A WAF in front of your app is the right place to draw the line. Here's how.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why L7 DDoS is tricky
&lt;/h2&gt;

&lt;p&gt;A network-layer DDoS is easy to spot — it's just volume. An application-layer attack blends in:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Requests hit real URLs with valid headers.&lt;/li&gt;
&lt;li&gt;They may come from many IPs (a botnet), so blocking by address alone doesn't scale.&lt;/li&gt;
&lt;li&gt;The damage comes from &lt;em&gt;cost&lt;/em&gt; — each request triggers expensive work: a database query, a render, an API call.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The goal isn't to crash your server with bandwidth; it's to make your app do so much real work that it falls over.&lt;/p&gt;

&lt;h2&gt;
  
  
  The defense playbook
&lt;/h2&gt;

&lt;p&gt;A few controls together blunt most L7 floods:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Filter the obviously bad.&lt;/strong&gt; Drop malformed requests, known attack signatures, and malformed HTTP before they reach your app.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limit per IP and per path.&lt;/strong&gt; Cap how much any single client can ask of a given endpoint.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Manage bots.&lt;/strong&gt; Identify and throttle automated clients; let humans through.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cache aggressively.&lt;/strong&gt; Serve static and repeatable responses from cache so they never reach your app.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Scale the origin&lt;/strong&gt; behind the WAF so a spike doesn't instantly exhaust capacity.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Where SafeLine fits
&lt;/h2&gt;

&lt;p&gt;SafeLine is a self-hosted WAF that runs as a reverse proxy in front of your app, so every request is inspected before it reaches your code:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;semantic detection engine&lt;/strong&gt; filters abnormal and malicious HTTP traffic, dropping the junk that would otherwise hit your app.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Rate limiting&lt;/strong&gt; caps requests per client and per path, so a flood can't monopolize your origin.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bot management&lt;/strong&gt; separates automated traffic from real users, letting you throttle or block the flood without hurting legitimate visitors.&lt;/li&gt;
&lt;li&gt;Because it runs at the edge of your stack, malicious requests are stopped early — before they trigger expensive backend work.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;SafeLine won't replace a full CDN-scale DDoS solution for nation-state-sized floods, but for the common L7 attacks that knock over small-to-mid web apps, it's a strong, self-hosted first line of defense.&lt;/p&gt;

&lt;h2&gt;
  
  
  Deploying it in front of your app
&lt;/h2&gt;

&lt;p&gt;Bring up SafeLine as the proxy in front of your service:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add your site and point its upstream at your app. Enable bot mitigation and set sensible rate limits on your heaviest endpoints. Traffic is now filtered and throttled at the edge, so a flood has to get past the WAF before it can touch your app.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can a WAF stop all DDoS attacks?
&lt;/h3&gt;

&lt;p&gt;It handles the common application-layer floods that target web apps. Very large volumetric attacks also need upstream/network mitigation, but most real-world incidents are L7 — exactly what a WAF addresses.&lt;/p&gt;

&lt;h3&gt;
  
  
  Won't rate limiting hurt real users during a spike?
&lt;/h3&gt;

&lt;p&gt;Set limits above normal human patterns. Legitimate traffic sails through; only abusive automated volume gets throttled.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does this replace caching and scaling?
&lt;/h3&gt;

&lt;p&gt;No — they're complementary. SafeLine filters and throttles; caching and scaling absorb the rest. Together they're far more resilient than any one control.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is this hard to self-host?
&lt;/h3&gt;

&lt;p&gt;The one-line installer brings up the whole stack as containers, and the console walks you through adding a site.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — your app now has a filtering and rate-limiting layer in front of it.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>devops</category>
      <category>selfhosted</category>
    </item>
    <item>
      <title>How to Stop Credential Stuffing Attacks: Protect Your Login Endpoints</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Mon, 28 Sep 2026 02:20:58 +0000</pubDate>
      <link>https://dev.to/lialiago/how-to-stop-credential-stuffing-attacks-protect-your-login-endpoints-1c1a</link>
      <guid>https://dev.to/lialiago/how-to-stop-credential-stuffing-attacks-protect-your-login-endpoints-1c1a</guid>
      <description>&lt;h1&gt;
  
  
  How to Stop Credential Stuffing Attacks: Protect Your Login Endpoints
&lt;/h1&gt;

&lt;p&gt;Credential stuffing is one of the most common — and most quietly damaging — attacks against web apps. It's not a clever exploit of a zero-day; it's brute force at scale, using passwords stolen from other breaches to log into accounts elsewhere. If your users reuse passwords (most do), some of those attempts will eventually work.&lt;/p&gt;

&lt;p&gt;The good news: credential stuffing is largely automated, and automated traffic is exactly what a WAF placed in front of your login endpoint is good at stopping. Here's a practical defense.&lt;/p&gt;

&lt;h2&gt;
  
  
  What credential stuffing looks like
&lt;/h2&gt;

&lt;p&gt;An attacker feeds a list of &lt;code&gt;email:password&lt;/code&gt; pairs — harvested from past breaches — into a script that fires login requests at your site. Two traits give it away:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Volume from few sources&lt;/strong&gt; — thousands of attempts from a narrow set of IPs or a botnet.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Automated behavior&lt;/strong&gt; — requests arrive faster than a human types, often with missing headers, fingerprinted clients, or shared user-agents.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Humans don't log in 500 times a minute. Bots do.&lt;/p&gt;

&lt;h2&gt;
  
  
  Layer your defenses
&lt;/h2&gt;

&lt;p&gt;No single control stops everything, but a few stack cleanly:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Rate limit the login path.&lt;/strong&gt; Cap how many attempts a single IP or account can make per minute. Genuine users rarely need more than a handful.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Detect and challenge bots.&lt;/strong&gt; Identify automated clients by behavior, not just IP, and challenge or block the ones that look like stuffing tools.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Add MFA or step-up auth&lt;/strong&gt; for suspicious logins. Even a correct password from a flagged session hits a second factor.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Watch for credential-stuffing signatures&lt;/strong&gt; — known-bad IP ranges, impossible travel, and repeated failures across many accounts.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Where SafeLine fits
&lt;/h2&gt;

&lt;p&gt;SafeLine is a self-hosted WAF that sits in reverse-proxy mode in front of your app, so every login request passes through it first. For credential stuffing specifically:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Its &lt;strong&gt;semantic detection engine&lt;/strong&gt; inspects requests and flags abnormal or malicious patterns before they reach your login handler.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Bot management&lt;/strong&gt; distinguishes automated clients from real users, so scripted stuffing traffic can be throttled or blocked.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Frequency/rate limiting&lt;/strong&gt; can be applied per path — including your login endpoint — to cap attempts and starve the attack of throughput.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;SafeLine won't replace MFA, but it removes the bulk of automated noise before it ever touches your application logic.&lt;/p&gt;

&lt;h2&gt;
  
  
  Putting it in front of login
&lt;/h2&gt;

&lt;p&gt;Deploy SafeLine as the reverse proxy in front of your service:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add your app and point its upstream at your login service. Then configure a frequency limit on the login route so no single source can hammer it. From that point, login attempts are filtered and rate-limited at the edge.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does a WAF alone stop credential stuffing?
&lt;/h3&gt;

&lt;p&gt;It removes the bulk of automated traffic, but pairing it with MFA and account-level lockouts closes the gaps a WAF can't see.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will rate limiting lock out real users?
&lt;/h3&gt;

&lt;p&gt;Set limits above normal human behavior (a few attempts per minute), and legitimate users are unaffected while bots are throttled.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is this the same as a brute-force attack?
&lt;/h3&gt;

&lt;p&gt;Similar, but credential stuffing uses &lt;em&gt;real&lt;/em&gt; leaked credentials rather than guessing randomly — which is why detecting automation matters more than detecting wrong passwords.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need to change my app code?
&lt;/h3&gt;

&lt;p&gt;No. SafeLine operates in front of your app as a proxy, so the defense is infrastructure, not application logic.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — your login endpoint now has a layer of automated protection in front of it.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>programming</category>
      <category>security</category>
      <category>tutorial</category>
      <category>devops</category>
    </item>
    <item>
      <title>Free WAF for Self-Hosted Apps: Protect Your Stack Without the Bill</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Thu, 24 Sep 2026 02:29:11 +0000</pubDate>
      <link>https://dev.to/lialiago/free-waf-for-self-hosted-apps-protect-your-stack-without-the-bill-33b4</link>
      <guid>https://dev.to/lialiago/free-waf-for-self-hosted-apps-protect-your-stack-without-the-bill-33b4</guid>
      <description>&lt;h1&gt;
  
  
  Free WAF for Self-Hosted Apps: Protect Your Stack Without the Bill
&lt;/h1&gt;

&lt;p&gt;If you self-host your apps, you've already committed to owning the infrastructure. That's good news for security: it means you can drop a free WAF in front of your stack without signing up for another monthly bill. For anyone running services on a VPS, a homelab, or a small cloud instance, a self-hosted WAF is some of the cheapest insurance you can buy.&lt;/p&gt;

&lt;p&gt;Here's how to protect self-hosted apps for free, and why SafeLine's Community Edition is a practical default.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why self-hosted apps need a WAF
&lt;/h2&gt;

&lt;p&gt;Any app you expose to the internet — a dashboard, an API, a CMS — is a target. Attackers scan for injection flaws, exposed admin panels, and known exploits automatically, around the clock. A WAF sits in front of your app and filters that traffic before it reaches your code.&lt;/p&gt;

&lt;p&gt;The catch with many WAFs is the price: cloud services bill per request or per protected app, which adds up fast across a self-hosted stack with several services. Running the WAF yourself removes that line item.&lt;/p&gt;

&lt;h2&gt;
  
  
  What "free" should still give you
&lt;/h2&gt;

&lt;p&gt;Not all free WAFs are equal. A free option is only worth it if it does the job:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Blocks the common web attacks (SQL injection, XSS) by default.&lt;/li&gt;
&lt;li&gt;Mitigates automated bots and credential stuffing.&lt;/li&gt;
&lt;li&gt;Deploys in minutes, not days.&lt;/li&gt;
&lt;li&gt;Runs on hardware you already have.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If a "free" tool needs you to write a pile of rules before it blocks anything, it isn't really free in time.&lt;/p&gt;

&lt;h2&gt;
  
  
  SafeLine Community Edition: a free self-hosted pick
&lt;/h2&gt;

&lt;p&gt;SafeLine is a self-hosted WAF by Chaitin, and its &lt;strong&gt;Community Edition&lt;/strong&gt; is free to run indefinitely. It covers &lt;strong&gt;up to 10 applications at 800 QPS&lt;/strong&gt;, which is plenty for a personal stack or a small set of self-hosted services.&lt;/p&gt;

&lt;p&gt;Under the hood it uses a semantic detection engine — it analyzes request intent rather than matching a static signature list — to catch injection and bot traffic. You get the protection without becoming a rule-tuning specialist.&lt;/p&gt;

&lt;h2&gt;
  
  
  Deploying it in a few minutes
&lt;/h2&gt;

&lt;p&gt;The one-line installer brings up the full stack (management console, detection engine, database, and cache) as containers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Then:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Add a site and set its upstream to your app (for example &lt;code&gt;http://127.0.0.1:8080&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Point your DNS or reverse proxy at SafeLine's listener.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;That's it — traffic now flows through the WAF before reaching your app. The minimum host is modest: about &lt;strong&gt;1 CPU, 1 GB RAM, and 5 GB disk&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  When free stops being enough
&lt;/h2&gt;

&lt;p&gt;The Community Edition's two caps are &lt;strong&gt;10 apps&lt;/strong&gt; and &lt;strong&gt;800 QPS&lt;/strong&gt;. If you run more services or push more traffic, the paid tiers lift those limits — Lite raises the app cap, and Pro removes it entirely — while keeping the same detection engine. You upgrade for headroom, not for better protection.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is this really free, or a trial?
&lt;/h3&gt;

&lt;p&gt;The Community Edition is free to run with no time limit. The only constraints are the 10-app and 800-QPS ceilings.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can it sit in front of multiple apps?
&lt;/h3&gt;

&lt;p&gt;Yes — up to 10 on the free tier. Each protected site or API counts as one app.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need to write detection rules?
&lt;/h3&gt;

&lt;p&gt;No. The semantic engine blocks common attacks out of the box; you tune only if you want to.&lt;/p&gt;

&lt;h3&gt;
  
  
  What if I outgrow the free tier later?
&lt;/h3&gt;

&lt;p&gt;Upgrading is a licensing change that raises the caps; your configuration and protected sites carry over.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Ready to protect your sites without paying for a cloud WAF?&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>programming</category>
      <category>security</category>
      <category>selfhosted</category>
      <category>devops</category>
    </item>
    <item>
      <title>Best Self-Hosted WAF for Small Business: What to Look For</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Thu, 24 Sep 2026 02:27:29 +0000</pubDate>
      <link>https://dev.to/lialiago/best-self-hosted-waf-for-small-business-what-to-look-for-40df</link>
      <guid>https://dev.to/lialiago/best-self-hosted-waf-for-small-business-what-to-look-for-40df</guid>
      <description>&lt;h1&gt;
  
  
  Best Self-Hosted WAF for Small Business: What to Look For
&lt;/h1&gt;

&lt;p&gt;Small businesses get attacked at roughly the same rate as everyone else, but they rarely have a security team to absorb the hit. A web application firewall (WAF) is one of the highest-leverage defenses you can put in front of your site — and for a small business, a &lt;strong&gt;self-hosted&lt;/strong&gt; WAF is often the most sensible way to run one.&lt;/p&gt;

&lt;p&gt;This guide walks through what actually matters when you're picking a WAF for a small business, and why a self-hosted option like SafeLine's free Community Edition deserves a serious look.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a small business actually needs from a WAF
&lt;/h2&gt;

&lt;p&gt;Enterprise WAF buying guides are full of features most small businesses will never touch. Strip it back to what you really need:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Protection from the common stuff&lt;/strong&gt; — SQL injection, cross-site scripting, and automated bots are the daily background noise of the internet. A WAF should block these out of the box, without you hand-writing rules.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Easy to set up&lt;/strong&gt; — if deployment takes a senior engineer a week, it won't happen. The best WAF for a small business is the one you'll actually turn on.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Low or no cost&lt;/strong&gt; — small margins mean every recurring subscription is a decision. Free is a strong default when the protection is real.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Minimal upkeep&lt;/strong&gt; — you don't have spare cycles to babysit it. It should run quietly once configured.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Why self-hosted fits small businesses
&lt;/h2&gt;

&lt;p&gt;A self-hosted WAF runs on infrastructure you already control — a spare VM, a small VPS, or a node in your existing stack. That changes the economics in your favor:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;No per-app or per-request billing.&lt;/strong&gt; Cloud WAFs often charge by traffic or by the number of protected services. Self-hosted shifts that to a flat server cost you're likely already paying.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Data stays with you.&lt;/strong&gt; Traffic inspection happens on your own hardware, which matters if you have residency or compliance preferences.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No lock-in.&lt;/strong&gt; You're not tied to one vendor's console, pricing changes, or feature gates.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The trade-off is real but small: you own the box, so you handle the host. For most small businesses that's a fair exchange for removing a monthly bill.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to evaluate options
&lt;/h2&gt;

&lt;p&gt;When you compare self-hosted WAFs, score them on four things:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Detection quality&lt;/strong&gt; — does it actually catch injection and bot traffic, or just pattern-match a stale signature list?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Install friction&lt;/strong&gt; — how many commands from zero to a protected site?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Resource footprint&lt;/strong&gt; — can it run on a modest box alongside other services?&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Price ceiling&lt;/strong&gt; — what do you pay as you grow?&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Where SafeLine fits
&lt;/h2&gt;

&lt;p&gt;SafeLine is a self-hosted WAF by Chaitin. Its free &lt;strong&gt;Community Edition&lt;/strong&gt; is a strong fit for small businesses because it covers the needs above without a subscription:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Free forever, self-hosted, and covers &lt;strong&gt;up to 10 applications at 800 QPS&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Ships with a semantic detection engine that blocks SQL injection, XSS, and bots without signature tuning.&lt;/li&gt;
&lt;li&gt;Installs with a single command and runs on a modest host — roughly &lt;strong&gt;1 CPU, 1 GB RAM, and 5 GB disk&lt;/strong&gt; at minimum.&lt;/li&gt;
&lt;li&gt;Management console on &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That combination — free, low-footprint, and genuinely protective — is exactly what most small businesses are looking for.&lt;/p&gt;

&lt;h2&gt;
  
  
  Getting started
&lt;/h2&gt;

&lt;p&gt;The fastest path is the one-line installer, which brings up the whole stack (console, detection engine, database, cache) as containers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Open the console, add your first site, and point its upstream at your app. If you grow past 10 apps or 800 QPS, paid tiers (Lite and Pro) raise the ceiling without changing how the WAF behaves.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Do I need a WAF if I already use HTTPS?
&lt;/h3&gt;

&lt;p&gt;Yes. HTTPS encrypts traffic; it doesn't stop an attacker from sending a malicious request to your login form. A WAF inspects what's inside the request.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is the free tier enough for a small business?
&lt;/h3&gt;

&lt;p&gt;Often, yes — 10 apps at 800 QPS covers a typical small-business footprint. Upgrade only when you outgrow those caps.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will running it myself be a lot of work?
&lt;/h3&gt;

&lt;p&gt;Minimal. Once installed and pointed at your sites, it runs as a background service. You check the console occasionally, like any other server component.&lt;/p&gt;

&lt;h3&gt;
  
  
  What if I don't have a spare server?
&lt;/h3&gt;

&lt;p&gt;A small VPS (the size that runs the console) is enough to start, and it can often share the host with other lightweight services.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Ready to protect your sites without paying for a cloud WAF?&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>tutorial</category>
      <category>selfhosted</category>
    </item>
    <item>
      <title>SafeLine WAF Pricing: Community vs Pro — Which Should You Choose?</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Wed, 23 Sep 2026 02:28:15 +0000</pubDate>
      <link>https://dev.to/lialiago/safeline-waf-pricing-community-vs-pro-which-should-you-choose-1jkb</link>
      <guid>https://dev.to/lialiago/safeline-waf-pricing-community-vs-pro-which-should-you-choose-1jkb</guid>
      <description>&lt;h1&gt;
  
  
  SafeLine WAF Pricing: Community vs Pro — Which Should You Choose?
&lt;/h1&gt;

&lt;p&gt;When you're picking a WAF, the pricing question usually isn't "can I afford it" but "which tier actually matches my setup." SafeLine makes this unusually simple: the free &lt;strong&gt;Community Edition&lt;/strong&gt; and the paid &lt;strong&gt;Pro&lt;/strong&gt; plan run the &lt;em&gt;same&lt;/em&gt; detection engine. You're not buying better protection as you pay more — you're buying more headroom.&lt;/p&gt;

&lt;p&gt;Here's how to decide which tier fits before you deploy.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tier&lt;/th&gt;
&lt;th&gt;Price&lt;/th&gt;
&lt;th&gt;Applications&lt;/th&gt;
&lt;th&gt;Throughput&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Community&lt;/td&gt;
&lt;td&gt;Free&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;td&gt;800 QPS&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Lite&lt;/td&gt;
&lt;td&gt;~$10 / month&lt;/td&gt;
&lt;td&gt;20&lt;/td&gt;
&lt;td&gt;higher cap&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Pro&lt;/td&gt;
&lt;td&gt;~$100 / month&lt;/td&gt;
&lt;td&gt;Unlimited&lt;/td&gt;
&lt;td&gt;higher cap&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Two things stand out. First, the free tier is genuinely usable — 10 apps at 800 QPS covers a lot of real workloads. Second, the only thing paid tiers change is capacity. The WAF behavior is identical.&lt;/p&gt;

&lt;h2&gt;
  
  
  Community: start here by default
&lt;/h2&gt;

&lt;p&gt;Unless you already know you'll exceed the free caps, begin on the Community Edition. It's free forever, self-hosted, and includes the full detection engine — SQL injection and XSS blocking, bot mitigation, and the reverse-proxy mode that sits in front of your upstreams.&lt;/p&gt;

&lt;p&gt;For a personal project, a small business with a handful of sites, or a staging environment, Community is often the only tier you'll ever need. There's no reason to pre-pay for headroom you haven't measured yet.&lt;/p&gt;

&lt;h2&gt;
  
  
  Pro: when scale is the constraint
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Pro&lt;/strong&gt; (~$100/month) removes the application cap entirely — &lt;strong&gt;unlimited applications&lt;/strong&gt; — and raises the throughput envelope well above the free tier's 800 QPS. Choose it when:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;You're protecting more than ten distinct apps or APIs.&lt;/li&gt;
&lt;li&gt;Your traffic regularly pushes past 800 QPS.&lt;/li&gt;
&lt;li&gt;You're standardizing WAF protection across a growing estate and don't want to count seats.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;You're not getting "more security" than Community; you're removing the two ceilings that would otherwise block you from scaling.&lt;/p&gt;

&lt;h2&gt;
  
  
  Lite: the middle step
&lt;/h2&gt;

&lt;p&gt;Between them sits &lt;strong&gt;Lite&lt;/strong&gt; (~$10/month), which doubles the app cap to &lt;strong&gt;20 applications&lt;/strong&gt;. If you've outgrown free but don't need unlimited scale, Lite is the quiet winner — a small monthly cost for a meaningful capacity bump.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to choose in practice
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Under 10 apps and under 800 QPS?&lt;/strong&gt; Stay on Community. Done.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Between 10 and 20 apps?&lt;/strong&gt; Lite covers you for about the price of a coffee per week.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Over 20 apps, or unpredictable growth?&lt;/strong&gt; Pro's unlimited cap removes the question.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Because the engine is the same everywhere, you can start free, watch your real app count and QPS in the console, and upgrade only when the numbers tell you to. There's no penalty for beginning on the free tier.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is Pro's WAF protection better than Community's?
&lt;/h3&gt;

&lt;p&gt;No — the detection engine is identical. Pro lifts the app and throughput limits; it doesn't change how attacks are detected or blocked.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I upgrade later without reconfiguring everything?
&lt;/h3&gt;

&lt;p&gt;Yes. Moving up is a licensing change that raises the caps. Your protected sites and configuration carry over.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why would I pay if the free tier has the same engine?
&lt;/h3&gt;

&lt;p&gt;Only if you exceed the 10-app or 800-QPS ceiling. If you don't, Community is the right answer and costs nothing.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is there a trial of Pro?
&lt;/h3&gt;

&lt;p&gt;The Community Edition is free to run indefinitely, so you can validate the engine on real traffic before deciding whether a paid tier's headroom is worth it.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Ready to protect your sites without paying for a cloud WAF?&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>programming</category>
      <category>security</category>
      <category>waf</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>SafeLine WAF Community Edition Limitations: What You Get for Free</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Wed, 23 Sep 2026 02:24:34 +0000</pubDate>
      <link>https://dev.to/lialiago/safeline-waf-community-edition-limitations-what-you-get-for-free-2lic</link>
      <guid>https://dev.to/lialiago/safeline-waf-community-edition-limitations-what-you-get-for-free-2lic</guid>
      <description>&lt;h1&gt;
  
  
  SafeLine WAF Community Edition Limitations: What You Get for Free
&lt;/h1&gt;

&lt;p&gt;SafeLine ships a free &lt;strong&gt;Community Edition&lt;/strong&gt; that you can run on your own server with no time limit and no feature trial. That makes it one of the few self-hosted WAFs you can actually put in front of production traffic without pulling out a credit card. But "free" does come with a ceiling, and it's worth knowing exactly where that ceiling sits before you commit.&lt;/p&gt;

&lt;p&gt;This article walks through what the Community Edition includes, the two hard limits you'll hit, and the point at which stepping up to a paid tier makes sense.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Community Edition actually gives you
&lt;/h2&gt;

&lt;p&gt;The free tier is not a stripped-down demo. It's the same detection engine that powers the paid plans, just with capacity caps. Concretely, the Community Edition covers:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Up to 10 applications&lt;/strong&gt; behind the WAF.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Up to 800 QPS&lt;/strong&gt; (queries per second) of protected traffic.&lt;/li&gt;
&lt;li&gt;The core semantic detection engine — the part that blocks SQL injection, XSS, bot traffic, and common web exploits without signature tuning.&lt;/li&gt;
&lt;li&gt;A management console, logs, and the reverse-proxy mode that sits in front of your upstream services.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If your setup fits inside those two numbers, you get the full protective value of SafeLine at zero cost. For a personal site, a small portfolio of internal tools, or a handful of low-traffic services, that's often the entire story.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where the limits actually bite
&lt;/h2&gt;

&lt;p&gt;There are exactly two hard constraints on the Community Edition, and both are about scale rather than features:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;10 applications.&lt;/strong&gt; Each protected site or API counts as one app. Once you pass ten, you can't add more on the free tier.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;800 QPS.&lt;/strong&gt; This is the throughput ceiling for inspected traffic. Bursts above it won't be denied outright, but you've left the envelope the free tier is sized for.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Notice what &lt;em&gt;isn't&lt;/em&gt; limited: there's no expiry, no blocked attack category, and no "contact sales after 14 days" wall. The limits are capacity, not capability. That's a meaningful difference from vendors who gate the actual protection behind a paid plan.&lt;/p&gt;

&lt;h2&gt;
  
  
  When it's time to move up
&lt;/h2&gt;

&lt;p&gt;If you're consistently near either cap — or you simply expect to grow past it — SafeLine offers two paid tiers that lift the ceilings rather than change how the WAF behaves:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Lite&lt;/strong&gt; — roughly &lt;strong&gt;$10/month&lt;/strong&gt;, raising the cap to &lt;strong&gt;20 applications&lt;/strong&gt;. A small step up for growing teams.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Pro&lt;/strong&gt; — roughly &lt;strong&gt;$100/month&lt;/strong&gt;, with &lt;strong&gt;unlimited applications&lt;/strong&gt; for larger estates.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Because the detection engine is identical across tiers, upgrading is about headroom, not about suddenly getting better protection. You move up when your app count or traffic volume demands it, not because the free tier is "missing" a feature.&lt;/p&gt;

&lt;h2&gt;
  
  
  Getting started on the free tier
&lt;/h2&gt;

&lt;p&gt;The fastest way to see the Community Edition in action is the one-line installer, which brings up the whole stack (console, detection engine, database, cache) as containers:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Once it finishes, open the console at &lt;code&gt;https://&amp;lt;your-server-ip&amp;gt;:9443&lt;/code&gt;, add your first site, and point its upstream at your app. You're now protecting up to 10 applications at 800 QPS for free.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is the Community Edition a time-limited trial?
&lt;/h3&gt;

&lt;p&gt;No. It's free to run indefinitely. The only constraints are the 10-app and 800-QPS ceilings.&lt;/p&gt;

&lt;h3&gt;
  
  
  What happens if I exceed 800 QPS?
&lt;/h3&gt;

&lt;p&gt;The limit is a sizing ceiling, not a hard cutoff that starts dropping traffic. But if you're consistently above it, a paid tier gives you the headroom to run comfortably.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I lose any protection features on the free tier?
&lt;/h3&gt;

&lt;p&gt;The detection capabilities are the same across tiers. Paid plans raise the app and throughput limits; they don't unlock a separate set of WAF features.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I switch from Community to Pro later?
&lt;/h3&gt;

&lt;p&gt;Yes. Since the engine is the same, moving up is a licensing change that lifts the caps — your configuration and protected sites carry over.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Ready to protect your sites without paying for a cloud WAF?&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>devops</category>
      <category>selfhosted</category>
    </item>
    <item>
      <title>SafeLine WAF Docker Compose Example</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Tue, 22 Sep 2026 03:23:26 +0000</pubDate>
      <link>https://dev.to/lialiago/safeline-waf-docker-compose-example-320e</link>
      <guid>https://dev.to/lialiago/safeline-waf-docker-compose-example-320e</guid>
      <description>&lt;h1&gt;
  
  
  SafeLine WAF Docker Compose Example
&lt;/h1&gt;

&lt;p&gt;SafeLine ships as a set of containers, and Docker Compose is the simplest way to bring up the whole stack — management console, detection engine, and the supporting database and cache — on a single host.&lt;/p&gt;

&lt;h2&gt;
  
  
  The fastest path
&lt;/h2&gt;

&lt;p&gt;The official one-line installer handles the compose file for you:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;bash &lt;span class="nt"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="si"&gt;$(&lt;/span&gt;curl &lt;span class="nt"&gt;-fsSLk&lt;/span&gt; https://waf.chaitin.com/release/latest/manager.sh&lt;span class="si"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="nt"&gt;--&lt;/span&gt; &lt;span class="nt"&gt;--en&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It writes a &lt;code&gt;docker-compose.yml&lt;/code&gt; in the SafeLine directory and starts the services. After it finishes, open the console at &lt;code&gt;https://&amp;lt;host-ip&amp;gt;:9443&lt;/code&gt; to add your protected sites.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the stack contains
&lt;/h2&gt;

&lt;p&gt;A typical SafeLine compose defines a few services working together:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Management console&lt;/strong&gt; — the web UI on &lt;code&gt;:9443&lt;/code&gt; where you configure sites and view logs.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Detection engine / proxy&lt;/strong&gt; — the component that actually inspects and forwards traffic on &lt;code&gt;:80&lt;/code&gt; / &lt;code&gt;:443&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Database&lt;/strong&gt; — stores configuration and records.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cache&lt;/strong&gt; — used for session and challenge state.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;An illustrative compose looks like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;services&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;safeline-mgt&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;            &lt;span class="c1"&gt;# management console&lt;/span&gt;
    &lt;span class="na"&gt;image&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;chaitin/safeline-mgt:latest&lt;/span&gt;
    &lt;span class="na"&gt;ports&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;9443:9443"&lt;/span&gt;&lt;span class="pi"&gt;]&lt;/span&gt;
  &lt;span class="na"&gt;safeline-detector&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;       &lt;span class="c1"&gt;# inspection + reverse proxy&lt;/span&gt;
    &lt;span class="na"&gt;image&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;chaitin/safeline-detector:latest&lt;/span&gt;
    &lt;span class="na"&gt;ports&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;[&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;80:80"&lt;/span&gt;&lt;span class="pi"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;443:443"&lt;/span&gt;&lt;span class="pi"&gt;]&lt;/span&gt;
  &lt;span class="na"&gt;safeline-pg&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;             &lt;span class="c1"&gt;# database&lt;/span&gt;
    &lt;span class="na"&gt;image&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;chaitin/safeline-pg:latest&lt;/span&gt;
  &lt;span class="na"&gt;safeline-redis&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;          &lt;span class="c1"&gt;# cache&lt;/span&gt;
    &lt;span class="na"&gt;image&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;chaitin/safeline-redis:latest&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Treat the exact image names, tags, and ports above as illustrative — pull the authoritative &lt;code&gt;docker-compose.yml&lt;/code&gt; from the official installer or docs, since these can change between versions.&lt;/p&gt;

&lt;h2&gt;
  
  
  Customizing
&lt;/h2&gt;

&lt;p&gt;Once it's up, common tweaks:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Persist data&lt;/strong&gt; — add named volumes for the database and config so they survive container recreation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Change ports&lt;/strong&gt; — if &lt;code&gt;:80&lt;/code&gt;/&lt;code&gt;:443&lt;/code&gt; are taken, map the proxy to different host ports and adjust your upstream/DNS accordingly.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Protect a site&lt;/strong&gt; — in the console, add a site whose upstream is your app (e.g. &lt;code&gt;http://127.0.0.1:8080&lt;/code&gt;).&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Do I need to write the compose myself?
&lt;/h3&gt;

&lt;p&gt;No — the installer generates it. Hand-writing is only if you want a custom layout.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I run it alongside other compose stacks?
&lt;/h3&gt;

&lt;p&gt;Yes; just keep the ports and volume names from colliding with other services.&lt;/p&gt;

&lt;h3&gt;
  
  
  Free tier?
&lt;/h3&gt;

&lt;p&gt;The Community Edition covers 10 apps at 800 QPS for free.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — a single compose stack gives you a running self-hosted WAF.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>docker</category>
      <category>webdev</category>
      <category>security</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to Set Up SafeLine WAF on Kubernetes</title>
      <dc:creator>Lia</dc:creator>
      <pubDate>Tue, 22 Sep 2026 03:21:31 +0000</pubDate>
      <link>https://dev.to/lialiago/how-to-set-up-safeline-waf-on-kubernetes-244c</link>
      <guid>https://dev.to/lialiago/how-to-set-up-safeline-waf-on-kubernetes-244c</guid>
      <description>&lt;h1&gt;
  
  
  How to Set Up SafeLine WAF on Kubernetes
&lt;/h1&gt;

&lt;p&gt;If your apps already run on Kubernetes, SafeLine fits right in — it's a containerized reverse-proxy WAF, so you deploy it like any other workload and route protected traffic through it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where SafeLine sits
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Client → Ingress / LoadBalancer → SafeLine Service → SafeLine pod → upstream app Service
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;SafeLine becomes the inspection tier in front of the services you want to protect. Each protected app is configured as an &lt;strong&gt;upstream&lt;/strong&gt; pointing at its in-cluster Service DNS (for example &lt;code&gt;http://my-app.default.svc.cluster.local:8080&lt;/code&gt;).&lt;/p&gt;

&lt;h2&gt;
  
  
  Approach
&lt;/h2&gt;

&lt;p&gt;The common pattern:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Deploy SafeLine&lt;/strong&gt; as a &lt;code&gt;Deployment&lt;/code&gt; + &lt;code&gt;Service&lt;/code&gt;. The Service exposes the console port (&lt;code&gt;:9443&lt;/code&gt;) for management and the proxy ports (&lt;code&gt;:80&lt;/code&gt; / &lt;code&gt;:443&lt;/code&gt;) that receive inspected traffic.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Point your Ingress&lt;/strong&gt; (or LoadBalancer) at the SafeLine Service for the hosts you want protected, instead of pointing directly at the app.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Add protected sites&lt;/strong&gt; in the SafeLine console (&lt;code&gt;https://&amp;lt;safeline-ip&amp;gt;:9443&lt;/code&gt;), with each upstream set to the target app's cluster-internal Service address.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;A minimal Deployment shape looks like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight yaml"&gt;&lt;code&gt;&lt;span class="na"&gt;apiVersion&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;apps/v1&lt;/span&gt;
&lt;span class="na"&gt;kind&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;Deployment&lt;/span&gt;
&lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;safeline&lt;/span&gt;
  &lt;span class="na"&gt;namespace&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;safeline&lt;/span&gt;
&lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
  &lt;span class="na"&gt;replicas&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="m"&gt;1&lt;/span&gt;
  &lt;span class="na"&gt;selector&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;matchLabels&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;app&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;safeline&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
  &lt;span class="na"&gt;template&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
    &lt;span class="na"&gt;metadata&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;labels&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;app&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;safeline&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
    &lt;span class="na"&gt;spec&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
      &lt;span class="na"&gt;containers&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
        &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="na"&gt;name&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;safeline&lt;/span&gt;
          &lt;span class="na"&gt;image&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s"&gt;chaitin/safeline:latest&lt;/span&gt;   &lt;span class="c1"&gt;# confirm the exact image/tag in the official docs&lt;/span&gt;
          &lt;span class="na"&gt;ports&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
            &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;containerPort&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;9443&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;      &lt;span class="c1"&gt;# management console&lt;/span&gt;
            &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;containerPort&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;80&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;        &lt;span class="c1"&gt;# proxy&lt;/span&gt;
            &lt;span class="pi"&gt;-&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;containerPort&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="nv"&gt;443&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;       &lt;span class="c1"&gt;# proxy (TLS)&lt;/span&gt;
          &lt;span class="na"&gt;resources&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt;
            &lt;span class="na"&gt;requests&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="pi"&gt;{&lt;/span&gt; &lt;span class="nv"&gt;cpu&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;1"&lt;/span&gt;&lt;span class="pi"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;memory&lt;/span&gt;&lt;span class="pi"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="s"&gt;1Gi"&lt;/span&gt; &lt;span class="pi"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Confirm the exact image, tag, and any companion services (database / cache the stack uses) against the official documentation before applying.&lt;/p&gt;

&lt;h2&gt;
  
  
  Persistence and scaling
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Mount a &lt;code&gt;PersistentVolumeClaim&lt;/code&gt; for SafeLine's config and logs so they survive pod restarts.&lt;/li&gt;
&lt;li&gt;For higher throughput, scale replicas and keep configuration consistent across them.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can one SafeLine protect several apps in the cluster?
&lt;/h3&gt;

&lt;p&gt;Yes — each protected site maps a domain to an in-cluster Service upstream, so multiple apps behind one SafeLine is straightforward.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where do I terminate TLS?
&lt;/h3&gt;

&lt;p&gt;Either at SafeLine or at your Ingress; forward to the upstream over HTTP or HTTPS as you prefer.&lt;/p&gt;

&lt;h3&gt;
  
  
  Free tier?
&lt;/h3&gt;

&lt;p&gt;The Community Edition covers 10 apps at 800 QPS for free.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;That's it — SafeLine runs as a normal Kubernetes workload and filters traffic to your services.&lt;/em&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;⭐ &lt;a href="https://github.com/chaitin/SafeLine" rel="noopener noreferrer"&gt;SafeLine WAF on GitHub&lt;/a&gt; — give it a star if you find it useful&lt;/li&gt;
&lt;li&gt;🔗 &lt;a href="https://docs.waf.chaitin.com/en/home" rel="noopener noreferrer"&gt;Official Docs&lt;/a&gt; — installation guide, configuration, and API reference&lt;/li&gt;
&lt;li&gt;🧪 &lt;a href="https://demo.waf.chaitin.com:9443/statistics" rel="noopener noreferrer"&gt;Live Demo&lt;/a&gt; — see the dashboard in action (no login required)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>webdev</category>
      <category>security</category>
      <category>devops</category>
      <category>kubernetes</category>
    </item>
  </channel>
</rss>
