| Port details |
- bunkerweb Self-hosted web application firewall and security platform
- 1.6.15_2 www
=0 1.6.11_1Version of this port present on the latest quarterly branch. - Maintainer: joneum@FreeBSD.org
 - Port Added: 2026-06-01 17:42:05
- Last Update: 2026-09-27 07:20:00
- Commit Hash: eb8f323
- Also Listed In: security
- License: AGPLv3
- WWW:
- https://github.com/bunkerity/bunkerweb
- Description:
- BunkerWeb is a security-focused reverse proxy and Web Application
Firewall (WAF) built on top of OpenResty (nginx with Lua support).
It integrates ModSecurity CRS, Lua-based request filtering,
rate limiting, automated TLS handling, an API service,
and a web management interface.
BunkerWeb supports both HTTP and stream-based reverse proxying
and can operate in standalone, containerized, or clustered
deployments.
¦ ¦ ¦ ¦ 
- Manual pages:
- FreshPorts has no man page information for this port.
- pkg-plist: as obtained via:
make generate-plist - USE_RC_SUBR (Service Scripts)
- bunkerweb
- bunkerweb_api
- bunkerweb_scheduler
- bunkerweb_ui
- Dependency lines:
-
- bunkerweb>0:www/bunkerweb
- To install the port:
- cd /usr/ports/www/bunkerweb/ && make install clean
- To add the package, run one of these commands:
- pkg install www/bunkerweb
- pkg install bunkerweb
NOTE: If this package has multiple flavors (see below), then use one of them instead of the name specified above.- PKGNAME: bunkerweb
- Flavors: there is no flavor information for this port.
- distinfo:
- TIMESTAMP = 1790016449
SHA256 (bunkerity-bunkerweb-1.6.15-v1.6.15_GH0.tar.gz) = 9f69a2d6cc649c6db5c79f6a93454cffa1b8677da96e73e2195eedc035f87515
SIZE (bunkerity-bunkerweb-1.6.15-v1.6.15_GH0.tar.gz) = 101332028
Packages (timestamps in pop-ups are UTC):
- Dependencies
- NOTE: FreshPorts displays only information on required and default dependencies. Optional dependencies are not covered.
- Runtime dependencies:
-
- openresty : www/openresty
- sudo : security/sudo
- py312-Jinja2>0 : devel/py-Jinja2@py312
- py312-pydantic-settings>0 : devel/py-pydantic-settings@py312
- py312-schedule>0 : devel/py-schedule@py312
- py312-user_agents>0 : devel/py-user_agents@py312
- py312-alembic>0 : databases/py-alembic@py312
- py312-sqlalchemy20>0 : databases/py-sqlalchemy20@py312
- py312-sqlite3>0 : databases/py-sqlite3@py312
- py312-pymysql>0 : databases/py-pymysql@py312
- cjson.so : devel/lua-cjson@lua51
- py312-bcrypt>0 : security/py-bcrypt@py312
- py312-biscuit-python>0 : security/py-biscuit-python@py312
- py312-passlib>0 : security/py-passlib@py312
- py312-docker>0 : sysutils/py-docker@py312
- py312-kubernetes>0 : sysutils/py-kubernetes@py312
- py312-psutil>0 : sysutils/py-psutil@py312
- py312-defusedcsv>=3.0.0 : devel/py-defusedcsv@py312
- py312-setuptools>0 : devel/py-setuptools@py312
- py312-openpyxl>0 : textproc/py-openpyxl@py312
- py312-qrcode>0 : textproc/py-qrcode@py312
- py312-regex>0 : textproc/py-regex@py312
- py312-cachelib>0 : www/py-cachelib@py312
- py312-fastapi>0 : www/py-fastapi@py312
- py312-flask>0 : www/py-flask@py312
- py312-Flask-Login>0 : www/py-flask-login@py312
- py312-flask-session>0 : www/py-flask-session@py312
- py312-flask_wtf>0 : www/py-flask-wtf@py312
- py312-gunicorn>0 : www/py-gunicorn@py312
- py312-requests>0 : www/py-requests@py312
- py312-slowapi>0 : www/py-slowapi@py312
- py312-uvicorn>0 : www/py-uvicorn@py312
- python3.12 : lang/python312
- Library dependencies:
-
- libmaxminddb.so : net/libmaxminddb
- liblua-5.1.so : lang/lua51
- There are no ports dependent upon this port
Configuration Options:
- No options to configure
- Options name:
- www_bunkerweb
- USES:
- lua:51 python:3.11+,run shebangfix
- pkg-message:
- For install:
- BunkerWeb has been installed.
BunkerWeb runs on OpenResty. Its settings are stored in the database
and are managed through the web interface on port 7000 or the API on
port 8888.
Enable the services at boot time with:
sysrc bunkerweb_scheduler_enable=YES
sysrc bunkerweb_api_enable=YES
sysrc bunkerweb_ui_enable=YES
sysrc bunkerweb_enable=YES
Start the services in this order:
service bunkerweb_scheduler start
service bunkerweb_api start
service bunkerweb_ui start
service bunkerweb start
The nginx configuration in /usr/local/etc/nginx/ is generated from the
templates in /usr/local/share/bunkerweb/common/confs/ and is rewritten
on every scheduler run, changes made there are lost.
Put your own nginx directives into the matching subdirectory of
/usr/local/etc/bunkerweb/configs/ instead. The scheduler imports them
into the database and includes them in the generated configuration.
- Master Sites:
|
| Commit History - (may be incomplete: for full details, see links to repositories near top of page) |
| Commit | Credits | Log message |
1.6.15_2 27 Sep 2026 07:20:00
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Make the scheduler and the API work together
The scheduler registered the instance with HTTP_PORT instead of
API_HTTP_PORT, so it never reached it and ran no jobs at all.
Run it as the worker user and share the directories with the API,
which replaces those files on a push. Point the remaining Linux paths
in the API and the config saver at their FreeBSD locations, teach the
reload path about the openresty binary, and let the worker reload
through the rc script, the fallback upstream already uses.
Sponsored by: Netzkommune GmbH |
1.6.15_1 24 Sep 2026 15:02:41
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Enable ModSecurity when the module is available
Render the ModSecurity directives only if
ngx_http_modsecurity_module.so is installed, like upstream does for
the stream module. Build www/openresty with the MODSECURITY option to
get it.
Point the remaining paths at their FreeBSD locations, error pages,
assets and rule files were read from /usr/share/bunkerweb.
Sponsored by: Netzkommune GmbH |
1.6.15 22 Sep 2026 04:25:33
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Update to 1.6.15
Fixes an unauthenticated RCE in the worker API (GHSA-xcv3-gjwr-rwxw),
a WAF filename bypass via RFC 2231 encoding (GHSA-cvfx-2ffg-cqmj) and
three API permission flaws.
1.6.15 imports Configurator in the scheduler and the web UI, so add
common/gen to their PYTHONPATH. Run the Alembic migration before the
scheduler starts, upstream does this in its systemd wrapper, without
it the scheduler dies on the new is_draft column.
Ship a sample api.yml, the API refused to start without that file, and
bind it to localhost by default. Drop the ModSecurity directives from
the reverse proxy and web UI templates too, OpenResty has no such
module.
Changelog: https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.15
Sponsored by: Netzkommune GmbH |
1.6.14_1 06 Sep 2026 21:13:42
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Fix antibot plugin and improve pkg-message
The antibot core plugin does require("base64"), but lbase64 is not in
the lua_package_path, so the module cannot be resolved. Add it.
The nginx configuration is generated by the scheduler at runtime, the
port does not install it. Describe that in the message, along with the
directory for own directives, and let the rc script bail out with a
clear message as long as the configuration has not been generated.
Reported by: netchild via private email
Sponsored by: Netzkommune GmbH |
1.6.14 28 Aug 2026 21:03:40
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Update to 1.6.14
Changelog: https://github.com/bunkerity/bunkerweb/releases/tag/v1.6.14
Sponsored by: Netzkommune GmbH |
1.6.13_3 27 Aug 2026 07:29:39
    |
Michael Osipov (michaelo)  |
security/py-biscuit-auth: Convert build to use PEP 517 and rename to PyPI name
* Rename port to PyPI name according to Python policy
* Move build completely to PEP 517
* Bump consumers: www/bunkerweb/Makefile
* Simplify Python discovery; the build frontend will pass the interpreter
New name: security/py-biscuit-python
Co-authored-by: Jochen Neumeister <joneum@FreeBSD.org>
PR: 297823
Approved by: joneum (maintainer)
Differential Revision: https://reviews.freebsd.org/D59133 |
1.6.13_2 06 Aug 2026 03:21:25
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Fix rc scripts for non-3.11 Python versions
The rc scripts hardcoded /usr/local/bin/python3.11, which only worked
while the tree default happened to be 3.11. With the default at 3.12
none of the three Python services could start. Substitute the
interpreter through %%PYTHON_VERSION%% instead.
While here, create /var/run/bunkerweb in the scheduler precmd. The
scheduler writes its own pid file below that directory and died with
FileNotFoundError on a fresh boot because nothing created it.
Sponsored by: Netzkommune GmbH |
1.6.13_1 06 Aug 2026 02:38:51
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Add missing setuptools run dependency
passlib/pwd.py imports pkg_resources at module level, and that module
lives in setuptools. Nothing in the dependency chain requested it, so
the import only succeeded as long as something else happened to pull
setuptools in. Upstream pins setuptools<81 in the scheduler
requirements for the same reason: pkg_resources is gone in 81.
While here, pin the py-biscuit-auth dependency to ${PY_FLAVOR} now
that the port has flavors.
Sponsored by: Netzkommune GmbH |
1.6.13 05 Aug 2026 16:58:23
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: Update to 1.6.13
This covers the 1.6.12 and 1.6.13 releases.
Security: session fixation on login and an open redirect via the
post-login "next" parameter in the web UI, a second open redirect in
the antibot post-challenge flow, and cache deletion routes that
bypassed authorization. Biscuit token generation now binds the Host
header, client IP and username as typed terms, and adds an optional
API_ALLOWED_HOSTS allowlist. Reverse DNS results are forward-confirmed
before an IGNORE_RDNS or GREYLIST_RDNS suffix match is honored, so a
self-configured PTR record no longer bypasses blocking. ACME challenge
tokens are validated against the base64url character set, closing a
path traversal through the internal API. TOTP verification is enforced
on the exact validation endpoint instead of any path containing /totp. (Only the first 15 lines of the commit message are shown above ) |
1.6.11_1 24 Jun 2026 14:30:59
    |
Jochen Neumeister (joneum)  |
www/openresty: Update to 1.31.1.1
Changelog: https://openresty.org/en/changelog-1031001.html
Sponsored by: Netzkommune GmbH |
1.6.11 01 Jun 2026 17:27:52
    |
Jochen Neumeister (joneum)  |
www/bunkerweb: add new port
BunkerWeb is an open-source next-generation web application firewall
(WAF) and security platform designed to protect and manage web services.
It provides integrated security features such as request filtering,
rate limiting, TLS management, GeoIP support and a web management
interface.
As this is a newly introduced port, users are encouraged to validate
their deployment before using it in production environments.
WWW: https://github.com/bunkerity/bunkerweb
Sponsored by: Netzkommune GmbH |