Back to articles
Technology Insight

Deploying BunkerWeb on Docker: The Ultimate Next-Gen WAF and Reverse Proxy for Automated Bot Protection

June 1, 2026

Introduction to Modern Web Security Challenges

In the contemporary digital landscape, web applications are under constant siege. From automated credential stuffing and scraping to sophisticated SQL injections and Distributed Denial of Service (DDoS) attacks, malicious bots account for a massive percentage of global internet traffic. For businesses and developers, safeguarding web assets is no longer optional—it is a critical operational requirement.

Traditionally, setting up a robust defense required complex architectures, combining traditional reverse proxies like Nginx with external Web Application Firewalls (WAF) such as ModSecurity. Managing these distinct layers often leads to configuration sprawl, performance bottlenecks, and maintenance headaches. Enter BunkerWeb: a next-generation, open-source web application firewall and reverse proxy designed to simplify and automate web security. When deployed via Docker, BunkerWeb provides a highly scalable, containerized defense mechanism that thwarts malicious actors right at the edge of your network.

What is BunkerWeb?

BunkerWeb is a comprehensive, security-first web server, reverse proxy, and WAF built on top of Nginx. It is designed to be "secure by default," meaning that it comes pre-configured with hard security settings out of the box, drastically reducing human error during deployment. Unlike traditional setups that require meticulous tuning to achieve baseline security, BunkerWeb integrates automation to dynamically adjust to threats.

Core Features of BunkerWeb

  • Automated Bot Detection: Uses advanced heuristics, threat intelligence feeds, and behavioral analysis to differentiate between legitimate users, search engine crawlers, and malicious bots.
  • Built-in Web Application Firewall (WAF): Powered by the Core Rule Set (CRS), it automatically mitigates common vulnerabilities listed in the OWASP Top 10, including Cross-Site Scripting (XSS), SQL Injection (SQLi), and Remote Code Execution (RCE).
  • Automatic Let's Encrypt SSL/TLS: Simplifies certificate management by automatically provisioning, configuring, and renewing Let's Encrypt SSL certificates for your domains.
  • Seamless Docker Integration: Native support for containerized environments, making it incredibly easy to manage via Docker Compose or Swarm, with dynamic configuration via environment variables.
  • Greylist and Blacklist Automation: Integrates with external threat feeds (like CrowdSec or abuse.ch) to automatically block known malicious IP addresses before they ever hit your upstream services.

Why Choose Docker for BunkerWeb Deployment?

Deploying security tools in a containerized environment offers distinct operational advantages. By utilizing Docker, you isolate your security proxy from the host operating system and other application services. This microservices architecture ensures that if one component requires updates or maintenance, the rest of the stack remains unaffected. Furthermore, Docker allows you to define your entire infrastructure as code, ensuring absolute consistency across development, staging, and production environments.

Step-by-Step Architecture Guide: BunkerWeb on Docker

To successfully implement BunkerWeb as your primary reverse proxy, it helps to understand the traffic flow. External users connect to BunkerWeb over ports 80 and 443. BunkerWeb inspects the incoming HTTP/HTTPS requests against its WAF rules and threat intelligence databases. If the request is verified as safe, BunkerWeb forwards the traffic to your internal application containers via an isolated Docker network.

Security Note: Your application containers should not expose their ports to the public host. They should only communicate within the internal Docker bridge network, ensuring that all external traffic is forced to pass through BunkerWeb's security screening.

Prerequisites

Before proceeding with the deployment, ensure that your environment meets the following baseline requirements:

  1. A Linux server (Ubuntu 22.04 LTS or newer recommended) with a public IP address.
  2. Docker and Docker Compose installed and updated to the latest versions.
  3. A registered domain name pointing to your server's public IP address (e.g., app.yourdomain.com).

Step 1: Preparing the Directory Structure

First, access your server via SSH and create a dedicated directory for your BunkerWeb project to maintain clean organization:

mkdir -p ~/bunkerweb-proxy && cd ~/bunkerweb-proxy

Step 2: Designing the Docker Compose Configuration

Create a file named docker-compose.yml inside your project directory. This configuration will define two services: the BunkerWeb security gateway and a sample web application (using Nginx as a placeholder for your backend service) to demonstrate reverse proxying.

Open the file with your preferred text editor and insert the following configuration structure:

version: '3.8'

services:
  bunkerweb:
    image: bunkerity/bunkerweb:latest
    container_name: bunkerweb
    ports:
      - "80:8080"
      - "443:8443"
    environment:
      - SERVER_NAME=app.yourdomain.com
      - MULTISITE=yes
      - app.yourdomain.com_REMOTE_REDIRECT=http://web-app:80
      - AUTO_LETS_ENCRYPT=yes
      - [email protected]
      - USE_ANTI_BOT=captcha
      - ANTI_BOT_CHALLENGE=cookie
      - USE_MODSECURITY=yes
      - USE_CORERULES=yes
    volumes:
      - bw_data:/data
    networks:
      - security_net
    restart: always

  web-app:
    image: nginx:alpine
    container_name: internal_web_app
    networks:
      - security_net
    restart: always

volumes:
  bw_data:

networks:
  security_net:
    driver: bridge

Step 3: Understanding Key Configuration Variables

Let's dissect the critical environment variables configured within the BunkerWeb container to understand how they enforce automated security:

  • SERVER_NAME & MULTISITE: Enables multi-site capability, allowing BunkerWeb to route traffic dynamically based on the requested host header.
  • _REMOTE_REDIRECT: Maps your public domain explicitly to the internal container name and port (http://web-app:80), abstracting the backend from the internet.
  • AUTO_LETS_ENCRYPT: Automates the generation and installation of valid SSL/TLS certificates, ensuring all transit data is encrypted.
  • USE_ANTI_BOT & ANTI_BOT_CHALLENGE: The first line of defense against automated scanners. It enforces subtle cookie challenges or interactive captchas if anomalous behavior is detected, immediately deflecting malicious bots.
  • USE_MODSECURITY & USE_CORERULES: Activates the core engine of the WAF along with the OWASP Core Rule Set to analyze parameters and headers for code injection vulnerabilities.

Deploying and Verifying Your Stack

With the file correctly configured, execute the following command to launch your containerized security stack in detached mode:

docker compose up -d

Docker will download the required images, establish the isolated security_net network, and initiate the services. You can monitor the startup logs and Let's Encrypt validation process by running:

docker compose logs -f bunkerweb

Once the logs indicate that the SSL certificates have been successfully generated, open a browser and navigate to [https://app.yourdomain.com](https://app.yourdomain.com). You should see the default Nginx welcome page, proving that BunkerWeb is successfully intercepting, cleaning, and proxying incoming web traffic.

Advanced Security Tuning: Eliminating False Positives

While BunkerWeb comes with exceptional defaults, strict security rules can occasionally trigger false positives on complex web applications. To tune your firewall, monitor the logs closely. If legitimate users report access denials (such as HTTP 403 errors), you can white-list specific rules or modify the sensitivity level by introducing the ALLOWED_METHODS or adjusting individual MODSECURITY_RULES variables within your docker-compose.yml file.

Regularly updating your container images is also essential. Since threat intelligence feeds change daily, scheduling a simple cron job to execute docker compose pull && docker compose up -d ensures your WAF is always armed with the latest signatures to neutralize zero-day exploits.

Conclusion

Implementing a robust security perimeter does not have to be an operational bottleneck. By deploying BunkerWeb on Docker, businesses can achieve enterprise-grade protection, automated bot blocking, and seamless reverse proxy routing with minimal configuration overhead. As malicious cyber activity continues to rise, embedding security directly into your container infrastructure ensures your web applications remain resilient, performant, and secure against ever-evolving threats.

Deploying BunkerWeb on Docker: The Ultimate Next-Gen WAF and Reverse Proxy for Automated Bot Protection | DPTCloud