Ask bots to do the work.
Browser challenges and verified sessions control admission. Start with Gate, then enable Shield for policy decisions and application inspection.
Proof of work · Bounded inspection · Zig
Sibuna protects websites and APIs with browser proof-of-work admission, application inspection and an optional management console.
Browser challenges and verified sessions control admission. Start with Gate, then enable Shield for policy decisions and application inspection.
Reverse-proxy and forward-auth deployments support existing ingress setups. Admitted multipart uploads, chunked bodies and WebSockets pass through to the origin.
The opt-in console brings traffic, incidents, challenges and policy management together. Read the design contracts, tests and measured workloads.
Try v0.2.0
Native packages cover Linux x86-64 and ARM64, macOS Intel and Apple Silicon, and Windows x86-64. Each archive includes license texts, dependency notices and a build manifest.
All downloads ↗curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/sibuna-linux-amd64.tar.gz
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
tar -xzf sibuna-linux-amd64.tar.gz
./sibuna --help
# Configure a trusted HTTPS ingress before deployment.Find your way through the system
The protocol, request pipeline, inspection bounds, algorithms and measurements. Also available as a PDF.
OperationsInstallation, ingress recipes, policies, persistent storage, GeoIP, the console and clustering.
Design discussionsArchitecture, alternatives, implementation boundaries and acceptance conditions in each Shibuna Discussion.
Know the deployment boundary
Terminate public HTTPS at a trusted ingress and keep Sibuna's listener private. Linux requires kernel 5.10 or later; macOS requires 15 or later; Windows requires Windows 10 or Server 2019 or later.
CLI and protocol reference ↗Inspection covers the first 8 KiB of supported request bodies. Uploaded file contents and WebSocket messages are not scanned. Forward-auth sees the metadata supplied by the ingress. Sibuna does not implement native ingress TLS, HTTP/2, global quotas or volumetric network mitigation.
The console is opt-in. Its strict performance isolation target has not formally passed. Published measurements identify the code revision and uncertainty.