Protect your Kubernetes workloads with ModSecurity and OWASP Core Rule Set (CRS) using native Kubernetes CRDs.
Define WAF rules using Kubernetes-native CRDs. No more managing complex config files.
Manage SecRules, SecActions and CRS policies directly in Kubernetes using
SecRule and SecAction resources.
Full support for the OWASP Core Rule Set. Import, customize and manage CRS rules as Kubernetes resources.
Powered by ModSecurity / Coraza. Battle-tested WAF engine with full SecLang compatibility.
Native integration as Envoy Gateway WAF policies using Kubernetes Gateway API. Apply rules at the gateway level.
Deploy as a sidecar container next to your application pods. Fine-grained per-workload protection using Coraza or ModSecurity.
Developed by Buzz-IT GmbH in Bern, Switzerland.
Expect breaking changes in future releases.