Securing Your VPS: Deploying Coraza WAF with Traefik v3 Reverse Proxy
Introduction: The Growing Necessity of VPS Security
In the modern cloud computing landscape, deploying applications on a Virtual Private Server (VPS) offers unparalleled flexibility and cost-effectiveness. However, exposing a VPS directly to the public internet invites a barrage of automated bots, vulnerability scanners, and sophisticated cyber attacks. Standard network-level firewalls are no longer sufficient; today's threat landscape requires application-layer inspection. This comprehensive guide walks you through building an enterprise-grade defense mechanism by integrating the Coraza Web Application Firewall (WAF) with the Traefik v3 Reverse Proxy. Together, they form a robust security barrier that filters malicious traffic before it ever reaches your backend services.
Understanding the Components: Traefik v3 and Coraza WAF
Why Traefik v3?
Traefik has established itself as a leading modern reverse proxy and load balancer, specifically designed for cloud-native architecture and containerized environments. Version 3 introduces enhanced performance, native support for HTTP/3, and a highly modular middleware system. Traefik automatically discovers services via provider integrations (like Docker or Kubernetes), making routing seamless and dynamic.
What is Coraza WAF?
Coraza is an open-source, enterprise-grade Web Application Firewall written in Go. It is designed to be a high-performance, drop-in replacement for legacy systems like ModSecurity. Coraza natively supports the OWASP Core Rule Set (CRS), allowing it to detect and block a wide array of web vulnerabilities, including SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and Remote Code Execution (RCE).
By combining Traefik's dynamic routing capabilities with Coraza's deep packet inspection, you achieve a highly scalable, low-latency security gateway tailored for modern VPS deployments.
Architecture Overview: How the Traffic Flows
Before diving into the configuration, it is essential to understand how requests travel through this security stack:
- The client initiates an HTTPS request directed at your VPS.
- Traefik v3 intercepts the incoming request, terminates the TLS connection, and handles SSL certificates automatically via Let's Encrypt.
- Traefik passes the request through its middleware chain, where the Coraza WAF middleware inspects the HTTP headers, query parameters, and request body against the OWASP Core Rule Set.
- If the request is deemed malicious, Coraza instructs Traefik to drop the connection and return a
403 Forbiddenstatus code. - If the request is clean, Traefik forwards it securely to the backend application container.
Step-by-Step Implementation Guide
Step 1: Preparing the VPS Environment
To implement this setup efficiently, we will use Docker and Docker Compose. Ensure your VPS is updated and has Docker installed. Create a dedicated project directory structure:
mkdir -p vps-security/{traefik,coraza,apps}Step 2: Configuring Traefik v3 with Coraza Plugins
Traefik v3 integrates with Coraza using its plugin system (Coraza WAF is available as a Yaegi-compatible middleware plugin for Traefik). Create a traefik.yml static configuration file inside the traefik/ directory:
experimental:
plugins:
coraza:
moduleName: "[github.com/corazawaf/coraza-traefik](https://github.com/corazawaf/coraza-traefik)"
version: "v1.0.0"
providers:
docker:
exposedByDefault: false
entryPoints:
web:
address: ":80"
http:
redirections:
entryPoint:
to: websecure
scheme: https
websecure:
address: ":443"Step 3: Defining the Coraza WAF Configurations
Next, you need to provide Coraza with its ruleset. Create a coraza.conf file inside the coraza/ directory. You can download the recommended default configuration file from the official Coraza repository. Ensure that SecRuleEngine is set appropriately:
- SecRuleEngine DetectionOnly: Analyzes requests and logs threats without blocking them. Highly recommended during the initial testing phase to prevent false positives.
- SecRuleEngine On: Actively blocks malicious requests, protecting your application in production.
To implement the OWASP Core Rule Set, download the CRS files into your configuration directory and include them via a SecComponent directive or direct file includes within your Coraza configuration layout.
Step 4: Crafting the Docker Compose Stack
Now, let's unify the architecture inside a docker-compose.yml file in the root directory. This stack initializes Traefik, sets up the Coraza middleware plugin, and deploys a sample backend application for testing purposes.
version: "3.8"
services:
traefik:
image: traefik:v3.0
container_name: traefik
ports:
- "80:80"
- "443:443"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- ./traefik/traefik.yml:/traefik.yml:ro
- ./coraza:/etc/coraza:ro
networks:
- web-proxy
backend-app:
image: nginx:alpine
container_name: secure-app
labels:
- "traefik.enable=true"
- "traefik.http.routers.app.rule=Host(`yourdomain.com`)"
- "traefik.http.routers.app.entrypoints=websecure"
- "traefik.http.routers.app.tls=true"
- "traefik.http.routers.app.middlewares=coraza-waf"
# Define Coraza Middleware Plugin
- "traefik.http.middlewares.coraza-waf.plugin.coraza.directivesFile=/etc/coraza/coraza.conf"
networks:
- web-proxy
networks:
web-proxy:
name: web-proxyTesting Your WAF and Verifying Logs
Once the containers are up and running via docker compose up -d, it is vital to test if the firewall is functioning as intended. You can simulate a common web attack using curl from an external machine.
Execute a standard Cross-Site Scripting (XSS) probe against your domain:
curl -i "[https://yourdomain.com/?search=](https://yourdomain.com/?search=);"If Coraza is set to SecRuleEngine On, you should immediately receive an HTTP 403 Forbidden response instead of the standard Nginx welcome page. Inspect the Traefik stdout logs or your designated Coraza audit log file to see the triggered rule IDs, confirming that the OWASP CRS successfully intercepted the payload.
Production Best Practices and Maintenance
Deploying a WAF is not a one-time event; it requires ongoing refinement to maintain optimal security without disrupting legitimate user behavior.
- Tuning False Positives: Real-world applications often trigger rules mistakenly. Always start in DetectionOnly mode, review the logs for safe requests that look suspicious to the system, and write anomaly score exclusions for those specific paths or parameters.
- Automated Rule Updates: The threat landscape evolves constantly. Set up a cron job or an automated pipeline to pull the latest versions of the OWASP Core Rule Set weekly.
- Performance Optimization: Deep body inspection increases CPU load. Limit the
SecRequestBodyLimitto a reasonable size (e.g., 10MB or less depending on your application needs) to protect your VPS from Denial of Service (DoS) attacks targeted at the WAF parser itself.
Conclusion
By implementing Coraza WAF alongside Traefik v3, you transform your VPS from a vulnerable target into a hardened application environment. This architecture offers a modern, high-performance substitute for legacy monolithic firewalls, combining cloud-native request routing with rigorous deep-packet evaluation. Prioritize security early in your deployment lifecycle to keep your enterprise data, user credentials, and server resources fully protected.
