DEV Community

Lia
Lia

Posted on

How to Secure a Website Without Cloudflare

How to Secure a Website Without Cloudflare

Cloudflare is the default answer to "how do I secure my site," but it isn't the only one — and it isn't always the right fit. If you'd rather keep control of your infrastructure, avoid a third-party sitting between you and every visitor, or just want a free starting point, you can secure a website without Cloudflare using a self-hosted stack.

Here's the layering that actually matters.

The security layers (none Cloudflare-dependent)

  1. TLS everywhere. Terminate HTTPS with a free certificate (Let's Encrypt or your CA of choice). Encrypted transport is table stakes, not a feature you rent.
  2. A WAF in front of your app. This is the layer Cloudflare's firewall usually provides. You can self-host it instead: a WAF like SafeLine runs as a reverse proxy in front of your service and filters injection, XSS, and bot traffic before it reaches your code.
  3. Rate limiting and bot management. Throttle abusive clients and separate automated traffic from real users at the edge.
  4. Hardened DNS and registrar. Lock your domain (registrar lock), use a reputable DNS provider, and restrict zone edits.
  5. Patching and backups. Most breaches exploit known vulnerabilities in unpatched software. Keep dependencies current and back up regularly.

Where SafeLine fits as the WAF layer

SafeLine is a self-hosted WAF by Chaitin. Its free Community Edition runs on your own hardware and covers up to 10 apps at 800 QPS, which is enough for most sites. It sits in reverse-proxy mode in front of your app, so every request is inspected before it hits your code — the same job Cloudflare's firewall does, just on infrastructure you control.

bash -c "$(curl -fsSLk https://waf.chaitin.com/release/latest/manager.sh)" -- --en
Enter fullscreen mode Exit fullscreen mode

After install, open the console at https://<your-server-ip>:9443, add your site, and point its upstream at your app. You now have a filtering layer in front of your traffic without handing your traffic to a third party.

The honest trade-off

Cloudflare also brings a global CDN and very large-scale DDoS scrubbing capacity. A self-hosted WAF handles the application layer (injection, XSS, bots, abuse) extremely well, but for nation-state-sized volumetric floods you'd still want upstream/network mitigation. For the overwhelming majority of sites — business apps, blogs, APIs, internal tools — a self-hosted WAF plus the hygiene above is a complete, Cloudflare-free security posture.

FAQ

Is a self-hosted WAF harder to run than Cloudflare?

It's a different operational model: you own the box instead of a dashboard. The install is one command, and day-to-day it runs as a background service.

Do I lose DDoS protection without Cloudflare?

You keep application-layer protection (the attacks that actually hit web apps). For massive volumetric attacks you'd add network-level mitigation, but most sites don't face those.

Can I still use a CDN?

Yes — pair a CDN for static delivery with SafeLine in front of your dynamic origin. They're complementary, not exclusive.

Is the WAF free?

The Community Edition is free to run indefinitely and covers up to 10 apps at 800 QPS.


That's it — a complete security stack you control, with no Cloudflare required.

Top comments (0)