Next-Gen Selfhosted Web Application Firewall (WAF) & Edge Reverse Proxy built in Go. Real-time threat defense, L7 traffic control, and unified admin console.
TypeScript
5
20 commits
updated Oct 3, 2026
Open-Source Web Application Firewall & Edge Security Gateway
High-performance reverse proxy delivering real-time threat defense, Layer 7 rate limiting, and dynamic zero-downtime policy control.
Aegis is an open-source, high-performance Web Application Firewall and reverse proxy designed to protect web applications, APIs, and microservices at the network edge. Positioned in front of your upstream services, Aegis inspects incoming HTTP and HTTPS traffic in real time, stopping cyber attacks, malicious bots, and abusive traffic surges before they can reach your backend infrastructure.
All routing rules, firewall policies, rate limits, and SSL certificates are managed dynamically through an integrated web console with zero downtime and no configuration restarts.
Run the universal installer on any modern Linux system:
curl -fsSL https://get.divinelab.io/installAegis.sh | sudo bash
Or via git clone:
git clone https://github.com/divinelabio/aegis.git
cd aegis
sudo bash install.sh
Deploy the complete Aegis stack with PostgreSQL and ClickHouse real-time analytics:
version: '3.8'
services:
aegis:
image: ghcr.io/divinelabio/aegis:latest
container_name: aegis_server
restart: unless-stopped
ports:
- "8080:8080" # Ingress Traffic & WAF Proxy
- "8081:8081" # Web Admin Console & Control API
environment:
AEGIS_ADMIN_PASSWORD: ${AEGIS_ADMIN_PASSWORD:-admin}
AEGIS_CONTROL_DB_HOST: postgres
AEGIS_CONTROL_DB_PORT: "5432"
AEGIS_ANALYTICS_HOST: clickhouse
AEGIS_ANALYTICS_PORT: "9000"
depends_on:
postgres:
condition: service_healthy
clickhouse:
condition: service_healthy
volumes:
- aegis_data:/var/lib/aegis/data
postgres:
image: postgres:16-alpine
container_name: aegis_postgres
restart: unless-stopped
environment:
POSTGRES_DB: aegis
POSTGRES_USER: aegis
POSTGRES_PASSWORD: ${AEGIS_CONTROL_DB_PASSWORD:-testdb}
volumes:
- postgres_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U aegis -d aegis"]
interval: 5s
timeout: 3s
retries: 5
clickhouse:
image: clickhouse/clickhouse-server:25.8
container_name: aegis_clickhouse
restart: unless-stopped
environment:
CLICKHOUSE_DB: aegis
CLICKHOUSE_USER: default
CLICKHOUSE_PASSWORD: ""
ports:
- "9000:9000"
- "8123:8123"
volumes:
- clickhouse_data:/var/lib/clickhouse
healthcheck:
test: ["CMD", "clickhouse-client", "--query", "SELECT 1"]
interval: 5s
timeout: 3s
retries: 10
volumes:
aegis_data:
postgres_data:
clickhouse_data:
Start the stack:
docker compose up -d
If you prefer to run Aegis natively without Docker, download the official pre-compiled package directly from GitHub Releases. Each release package is completely self-contained and includes the executable with the embedded Web Admin UI, default config.yaml, and rulesets.
# 1. Download and extract the latest release package
curl -sSL https://github.com/divinelabio/aegis/releases/latest/download/aegis-linux-amd64.tar.gz | tar -xz
# 2. (Optional) Move executable to system PATH
sudo mv aegis /usr/local/bin/
sudo mv aegisctl /usr/local/bin/ 2>/dev/null || true
# 3. Start Aegis WAF
aegis run -c config.yaml
aegis-windows-amd64.zip from GitHub Releases..\aegis.exe run -c config.yaml
Web Admin Console: Once running, navigate to
http://<your-server-ip>:8081in your browser. (The full web dashboard is embedded inside the binary; no Node.js or web server required).
To contribute to Aegis or build directly from the latest commit:
web/admin)# 1. Clone the repository
git clone https://github.com/divinelabio/aegis.git
cd aegis
# 2. Build the binaries using Makefile
make build
# Or compile directly with the Go toolchain:
go build -ldflags="-s -w" -o bin/aegis ./cmd/aegis-server
go build -ldflags="-s -w" -o bin/aegisctl ./cmd/aegisctl
# 3. (Optional) Rebuild the Web Admin UI if you modify frontend code
npm run admin:build
# 4. Start Aegis from source
./bin/aegis run -c config.yaml
Aegis Community Edition provides complete Layer-7 WAF protection. For enterprise environments requiring automated bot defense, external threat intelligence feeds, and compliance scanning, advanced capabilities can be unlocked with a license from DivineLab:
To upgrade or obtain an evaluation license, visit divinelab.io/products/aegis.
Aegis is licensed under the Business Source License 1.1 (BSL 1.1).
For enterprise licensing, OEM distribution, and production support, visit divinelab.io or contact contact@divinelab.io.
Next-Gen Selfhosted Web Application Firewall (WAF) & Edge Reverse Proxy built in Go. Real-time threat defense, L7 traffic control, and unified admin console.
TypeScript
5
20 commits
updated Oct 3, 2026
Open-Source Web Application Firewall & Edge Security Gateway
High-performance reverse proxy delivering real-time threat defense, Layer 7 rate limiting, and dynamic zero-downtime policy control.
Aegis is an open-source, high-performance Web Application Firewall and reverse proxy designed to protect web applications, APIs, and microservices at the network edge. Positioned in front of your upstream services, Aegis inspects incoming HTTP and HTTPS traffic in real time, stopping cyber attacks, malicious bots, and abusive traffic surges before they can reach your backend infrastructure.
All routing rules, firewall policies, rate limits, and SSL certificates are managed dynamically through an integrated web console with zero downtime and no configuration restarts.
Run the universal installer on any modern Linux system:
curl -fsSL https://get.divinelab.io/installAegis.sh | sudo bash
Or via git clone:
git clone https://github.com/divinelabio/aegis.git
cd aegis
sudo bash install.sh
Deploy the complete Aegis stack with PostgreSQL and ClickHouse real-time analytics:
version: '3.8'
services:
aegis:
image: ghcr.io/divinelabio/aegis:latest
container_name: aegis_server
restart: unless-stopped
ports:
- "8080:8080" # Ingress Traffic & WAF Proxy
- "8081:8081" # Web Admin Console & Control API
environment:
AEGIS_ADMIN_PASSWORD: ${AEGIS_ADMIN_PASSWORD:-admin}
AEGIS_CONTROL_DB_HOST: postgres
AEGIS_CONTROL_DB_PORT: "5432"
AEGIS_ANALYTICS_HOST: clickhouse
AEGIS_ANALYTICS_PORT: "9000"
depends_on:
postgres:
condition: service_healthy
clickhouse:
condition: service_healthy
volumes:
- aegis_data:/var/lib/aegis/data
postgres:
image: postgres:16-alpine
container_name: aegis_postgres
restart: unless-stopped
environment:
POSTGRES_DB: aegis
POSTGRES_USER: aegis
POSTGRES_PASSWORD: ${AEGIS_CONTROL_DB_PASSWORD:-testdb}
volumes:
- postgres_data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U aegis -d aegis"]
interval: 5s
timeout: 3s
retries: 5
clickhouse:
image: clickhouse/clickhouse-server:25.8
container_name: aegis_clickhouse
restart: unless-stopped
environment:
CLICKHOUSE_DB: aegis
CLICKHOUSE_USER: default
CLICKHOUSE_PASSWORD: ""
ports:
- "9000:9000"
- "8123:8123"
volumes:
- clickhouse_data:/var/lib/clickhouse
healthcheck:
test: ["CMD", "clickhouse-client", "--query", "SELECT 1"]
interval: 5s
timeout: 3s
retries: 10
volumes:
aegis_data:
postgres_data:
clickhouse_data:
Start the stack:
docker compose up -d
If you prefer to run Aegis natively without Docker, download the official pre-compiled package directly from GitHub Releases. Each release package is completely self-contained and includes the executable with the embedded Web Admin UI, default config.yaml, and rulesets.
# 1. Download and extract the latest release package
curl -sSL https://github.com/divinelabio/aegis/releases/latest/download/aegis-linux-amd64.tar.gz | tar -xz
# 2. (Optional) Move executable to system PATH
sudo mv aegis /usr/local/bin/
sudo mv aegisctl /usr/local/bin/ 2>/dev/null || true
# 3. Start Aegis WAF
aegis run -c config.yaml
aegis-windows-amd64.zip from GitHub Releases..\aegis.exe run -c config.yaml
Web Admin Console: Once running, navigate to
http://<your-server-ip>:8081in your browser. (The full web dashboard is embedded inside the binary; no Node.js or web server required).
To contribute to Aegis or build directly from the latest commit:
web/admin)# 1. Clone the repository
git clone https://github.com/divinelabio/aegis.git
cd aegis
# 2. Build the binaries using Makefile
make build
# Or compile directly with the Go toolchain:
go build -ldflags="-s -w" -o bin/aegis ./cmd/aegis-server
go build -ldflags="-s -w" -o bin/aegisctl ./cmd/aegisctl
# 3. (Optional) Rebuild the Web Admin UI if you modify frontend code
npm run admin:build
# 4. Start Aegis from source
./bin/aegis run -c config.yaml
Aegis Community Edition provides complete Layer-7 WAF protection. For enterprise environments requiring automated bot defense, external threat intelligence feeds, and compliance scanning, advanced capabilities can be unlocked with a license from DivineLab:
To upgrade or obtain an evaluation license, visit divinelab.io/products/aegis.
Aegis is licensed under the Business Source License 1.1 (BSL 1.1).
For enterprise licensing, OEM distribution, and production support, visit divinelab.io or contact contact@divinelab.io.