Back to articles
Technology Insight

Securing Web Applications Effortlessly: A Guide to Deploying BunkerWeb WAF on VPS with Docker

May 29, 2026

Introduction: The Growing Necessity of Automating Web Security

In the contemporary digital landscape, web applications have become the primary target for cyber threats. From SQL injections and Cross-Site Scripting (XSS) to aggressive brute-force attacks and malicious bot scrapers, the vulnerabilities are vast and continuously evolving. For businesses operating on Virtual Private Servers (VPS), maintaining a robust defense mechanism often demands significant time, expertise, and manual intervention.

Traditionally, deploying a Web Application Firewall (WAF) required complex configurations, deep understanding of security rules, and constant tweaking. However, the rise of containerized security solutions has shifted the paradigm. BunkerWeb emerges as a cutting-edge, open-source WAF designed to maximize automation while providing enterprise-grade security. Built on top of the highly performant Nginx web server and deeply integrated with the Docker ecosystem, BunkerWeb automates critical security functions—including Let's Encrypt SSL provisioning and automated bot detection. This guide provides a comprehensive roadmap for deploying BunkerWeb on your VPS to secure your applications efficiently.

What is BunkerWeb and Why Choose It?

BunkerWeb is a modern web application firewall that integrates seamlessly into containerized environments. It acts as a reverse proxy, inspecting all incoming traffic before it reaches your backend applications. Unlike traditional WAFs that act as rigid gatekeepers, BunkerWeb is highly adaptive, customizable, and automated out of the box.

Several key advantages make BunkerWeb an ideal choice for businesses and developers managing VPS infrastructure:

  • Maximum Automation via Docker: Configuration is handled primarily through environment variables, eliminating the need to write complex Nginx configuration files by hand.
  • Automated Let's Encrypt Integration: BunkerWeb communicates directly with Let's Encrypt to automatically provision, configure, and renew SSL/TLS certificates, ensuring your sites are always encrypted via HTTPS.
  • Advanced Bot Detection and Mitigation: It features built-in mechanisms to detect and block malicious bots, automated scrapers, and scanners through a combination of heuristics, challenge-response systems (like Captchas), and blacklists.
  • Security by Default: It comes pre-configured with the OWASP Core Rule Set (CRS), providing instant protection against the top ten web application security risks.

Prerequisites for Deployment

Before initiating the installation process, ensure your VPS environment meets the following baseline requirements:

  1. Operating System: A clean installation of a modern Linux distribution, preferably Ubuntu 22.04 LTS or newer.
  2. Docker and Docker Compose: Docker Engine and the Docker Compose plugin must be installed and running on the host system.
  3. Domain Names: Properly configured DNS records (A/AAAA) pointing your domain names to the public IP address of your VPS.
  4. Network Accessibility: Standard web ports (Port 80 for HTTP and Port 443 for HTTPS) must be completely open and unblocked by any external cloud firewalls or cloud provider security groups.

Step-by-Step Architecture and Configuration

Step 1: Setting Up the Directory Structure

To keep the deployment organized and maintainable, establish a dedicated directory structure for BunkerWeb and its configurations. Connect to your VPS via SSH and execute the following commands:

mkdir -p ~/bunkerweb-setup/bw-data
cd ~/bunkerweb-setup

The bw-data directory will serve as a persistent volume to store Let's Encrypt certificates, cache files, and security databases, ensuring data persistence across container restarts.

Step 2: Crafting the Docker Compose File

Create a docker-compose.yml file within the directory. This configuration defines BunkerWeb as the main entry point (reverse proxy) and includes a sample backend web application (such as a basic Nginx service) to demonstrate how traffic is routed and protected securely.

Open the file with your preferred text editor (e.g., nano docker-compose.yml) and populate it with the following configuration:

version: '3.8' services: bunkerweb: image: bunkerity/bunkerweb:1.5.11 container_name: bunkerweb ports: - "80:8080" - "443:8443" volumes: - ./bw-data:/data environment: - SERVER_NAME=example.com [www.example.com](https://www.example.com) - API_WHITELIST_IP=127.0.0.1/32 - AUTO_LETS_ENCRYPT=yes - [email protected] - USE_ANTI_BOT=captcha - ANTI_BOT_CHALLENGE=recaptcha - SERVE_FILES=no - USE_REVERSE_PROXY=yes - REVERSE_PROXY_URL=/ - REVERSE_PROXY_HOST=http://backend-app:80 restart: always networks: - web-network backend-app: image: nginx:alpine container_name: backend-app restart: always networks: - web-network networks: web-network: driver: bridge

Note: Replace example.com and [email protected] with your actual domain and administrative email address respectively.

Step 3: Understanding the Security Environment Variables

The true power of BunkerWeb lies in its declarative configuration via environment variables. Let's break down the critical security directives used in the file above:

  • AUTO_LETS_ENCRYPT=yes: Instructs BunkerWeb to handle the entire ACME protocol workflow automatically, fetching and maintaining valid SSL certificates for all domains listed in SERVER_NAME.
  • USE_ANTI_BOT=captcha: Activates the automated bot mitigation layer. When suspicious traffic patterns are recognized, BunkerWeb will challenge the client using a Captcha validation mechanism before granting access to the application.
  • REVERSE_PROXY_HOST: Directs all legitimate, cleaned web traffic securely to the internal Docker network address of your application container, shielding your backend service from direct exposure to the public internet.

Deploying and Verifying the WAF

With the configuration file successfully constructed, execute the following command to deploy the services in detached mode:

docker compose up -d

BunkerWeb will initialize, generate internal configurations, and automatically contact Let's Encrypt to request your SSL certificates. You can monitor this automated initialization process by inspecting the real-time container logs:

docker compose logs -f bunkerweb

Once the logs indicate that the SSL certificates have been successfully issued, navigate to [https://example.com](https://example.com) via a web browser. You should see the default page of your backend application, completely secured over a verified HTTPS connection.

Advanced Bot Protection and Tweaking

While the baseline configuration offers robust security, production business environments often require fine-grained controls to prevent false positives and block sophisticated threats. BunkerWeb allows you to integrate commercial threat intelligence and configure automatic IP blocking via specialized environment variables.

Integrating External Blacklists

To further fortify your server against known malicious nodes, spam networks, and tor exit nodes, you can enforce the use of automated external blacklists by appending the following variables to your BunkerWeb service configuration:

      - USE_DNSBL=yes
      - DNSBL_PROVIDERS=bl.spamcop.net sbl.spamhaus.org
      - USE_BANNED_COUNTRIES=yes
      - BANNED_COUNTRIES=RU CN IR

In this example, BunkerWeb checks incoming requests against renowned DNS Blackhole Lists (DNSBL) and entirely drops connections originating from specified geographic regions where your business does not operate, drastically reducing the overall attack surface of your server.

Conclusion: Scalable and Automated Infrastructure Defense

Managing server security no longer requires hours of manual maintenance or expensive proprietary hardware firewalls. By combining the flexibility of Docker with the automated capabilities of BunkerWeb, businesses can achieve a resilient, self-sustaining security perimeter right on their VPS. From managing renewals of Let's Encrypt SSL certificates to filtering bad bots and patching web vulnerabilities via the OWASP rule sets, BunkerWeb handles critical defenses autonomously. This allows your development and operations teams to focus entirely on building core product features with the peace of mind that your infrastructure remains continuously protected.

Securing Web Applications Effortlessly: A Guide to Deploying BunkerWeb WAF on VPS with Docker | DPTCloud