Proof of work · Bounded inspection · Zig

Protect your site.
Keep the work bounded.

Sibuna protects websites and APIs with browser proof-of-work admission, application inspection and an optional management console.

Open source · Engine: LGPL 3.0 · Console: AGPL 3.0 · v0.2.0

An admission decision before your application.
The protected request path A client reaches an HTTPS ingress. Sibuna admits, challenges or refuses the request before an admitted request reaches the origin application. ClientHTTPS ingress SibunaOrigin app private HTTP/1.1admitted challengeor refuse
Reverse proxy or forward-auth One executable
01 / Govern admission

Ask bots to do the work.

Browser challenges and verified sessions control admission. Start with Gate, then enable Shield for policy decisions and application inspection.

02 / Protect applications

Keep requests flowing.

Reverse-proxy and forward-auth deployments support existing ingress setups. Admitted multipart uploads, chunked bodies and WebSockets pass through to the origin.

03 / Operate with evidence

See the decisions.

The opt-in console brings traffic, incidents, challenges and policy management together. Read the design contracts, tests and measured workloads.

Try v0.2.0

Download.
Verify. Configure.

Native packages cover Linux x86-64 and ARM64, macOS Intel and Apple Silicon, and Windows x86-64. Each archive includes license texts, dependency notices and a build manifest.

All downloads ↗
TERMINAL · LINUX x86-64
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/sibuna-linux-amd64.tar.gz
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
tar -xzf sibuna-linux-amd64.tar.gz
./sibuna --help

# Configure a trusted HTTPS ingress before deployment.

Find your way through the system

Learn it. Use it. Question it.

Know the deployment boundary

Application protection.
Explicit limits.

Terminate public HTTPS at a trusted ingress and keep Sibuna's listener private. Linux requires kernel 5.10 or later; macOS requires 15 or later; Windows requires Windows 10 or Server 2019 or later.

CLI and protocol reference ↗

Inspection covers the first 8 KiB of supported request bodies. Uploaded file contents and WebSocket messages are not scanned. Forward-auth sees the metadata supplied by the ingress. Sibuna does not implement native ingress TLS, HTTP/2, global quotas or volumetric network mitigation.

The console is opt-in. Its strict performance isolation target has not formally passed. Published measurements identify the code revision and uncertainty.

Console contract · Architecture whitepaper · Book PDF

Search the documentation