Proof-of-work admission and a bounded web application firewall with an opt-in management console.
See the code
A simple and lightweight web application firewall to protect websites and APIs without CAPTCHAs.
Features • Quickstart • How It Works • Architecture • Deployment • Configuration • Philosophy • Documentation
sibuna is an open-source web application firewall (WAF) and anti-crawler daemon. It sits in front of your web application as a protective reverse proxy, or alongside your existing reverse proxy (such as Caddy, Nginx, or Traefik) as an authorization gate.
Instead of subjecting human visitors to frustrating image CAPTCHAs or privacy-invasive tracking scripts, Sibuna asks client browsers to solve a background computational puzzle whose cost depends on the configured difficulty and client hardware. Instead of requiring sprawling container clusters, external databases, or heavy interpreters, Sibuna runs as a single, self-contained executable with predictable, bounded memory.
Following the modular design of raylib, Sibuna is divided into small, single-purpose subsystems:
┌────────────────────────────────────────────────────────────────────────┐
│ SIBUNA SUBSYSTEMS │
├──────────────┬─────────────────────────────────────────────────────────┤
│ socket │ Native socket operations and interruption ownership │
│ net │ Zero-copy HTTP/1.1 stream parser & reverse proxy relay │
│ crypto │ Proof of Sequential Work (PoSW), Hashcash & BLAKE3 MAC │
│ policy │ Aho–Corasick signatures, Radix CIDR trie & semantic WAF │
│ challenge │ Stateless challenge coordinator & adaptive difficulty │
│ store │ 16-shard GCRA rate limiter & Robin Hood spent set │
│ edge │ Embedded Zaxonlite store (replicated SQLite Multi-Paxos)│
│ console │ WebAssembly operator UI, WebSocket telemetry & GeoIP │
└──────────────┴─────────────────────────────────────────────────────────┘
Sibuna provides two operational surfaces within the same executable:
┌─────────────────────────────────────────┐
│ Incoming Request │
└────────────────────┬────────────────────┘
│
[ Surface 1: Gate (--gate) ]
• Proof-of-work admission & sessions
• Bot signatures & Radix CIDR checks
• Atomic GCRA rate limiting & honeypots
│
▼ Admitted
[ Surface 2: Shield (--shield, default) ]
• Inline semantic attack inspection
• SQL injection & XSS automata
• Path traversal & shell execution filters
│
▼ Passed
┌─────────────────────────────────────────┐
│ Upstream Origin │
└─────────────────────────────────────────┘
Download a package from Releases, or build from source.
The v0.2.0 packages include the engine, embedded storage, browser solver and management console.
Clustering requires a separate -Dcluster=true source build with OpenSSL 3.
| Platform | Package | Requirements |
|---|---|---|
| Linux x86-64 | sibuna-linux-amd64.tar.gz | Linux 5.10 or later; statically linked musl |
| Linux ARM64 | sibuna-linux-arm64.tar.gz | Linux 5.10 or later; statically linked musl |
| macOS Apple Silicon | sibuna-macos-arm64.tar.gz | macOS 15 or later |
| macOS Intel | sibuna-macos-amd64.tar.gz | macOS 15 or later |
| Windows x86-64 | sibuna-windows-amd64.zip | Windows 10 / Server 2019 or later; native sibuna.exe |
macOS builds are unsigned. Packages include license texts, corresponding-source links and a
sibuna.build.json manifest. Verify the archive against the release's SHA256SUMS before use.
On Windows, extract the ZIP and run .\sibuna.exe --help from PowerShell. Use Ctrl+C for
ordered shutdown and restrict seed, credential and data files with Windows ACLs.
For Linux x86-64:
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/sibuna-linux-amd64.tar.gz
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
tar -xzf sibuna-linux-amd64.tar.gz
(umask 077; openssl rand -hex 32 > sibuna.seed)
./sibuna --version
./sibuna --host 127.0.0.1 --port 8080 --upstream-port 3000 --secret-file ./sibuna.seed
Terminate public HTTPS at your ingress and keep Sibuna's listener private; see deployment limits and the operations guide.
Use Zig 0.17.0, the checksum-pinned release toolchain. The storage libraries include
reviewable compatibility sources in vendor/; original release digests are recorded there.
# Clone the repository
git clone https://github.com/insanai/sibuna.git
cd sibuna
# Compile optimized release binary
python3 tools/prepare_build.py
zig build -Doptimize=fast
The resulting standalone binary is located at ./zig-out/bin/sibuna.
Point Sibuna to your existing web service (for example, a local server on port 3000):
./zig-out/bin/sibuna --port 8080 --upstream-port 3000 --secret-file /run/sibuna.seed
Open http://localhost:8080 in your browser. Your application is now protected.
Note on secrets: The seed file contains 32 raw bytes (or 64 hex characters) used to sign session tokens. You can also supply the seed via the SIBUNA_SECRET environment variable. If omitted, Sibuna generates a secure random seed at startup; sessions then expire when the process restarts.
Most web security today relies on interrogation: a security guard stops you at the doorway, holds up blurry photos, and demands that you identify every traffic light before you are allowed in. It treats every human customer like a suspected intruder, frustrates real people, and tracks their identity across the internet.
Sibuna replaces the interrogation room with a simple physical principle: a revolving door and a wristband.
[ Real Human Visitor ] [ Automated Botnet / Scraper ]
│ │
│ Walks in normally │ Tries to force 50,000 requests/sec
▼ ▼
┌──────────────────┐ ┌──────────────────┐
│ Revolving Door │ ◄─── Effortless push (100ms) │ Revolving Door │ ◄─── Impossible resistance
│ (Proof of Work) │ Handled silently in background │ (Proof of Work) │ Attacker's CPU burns out
└────────┬─────────┘ └────────┬─────────┘
│ │
▼ Receives Wristband ▼ Blocked at the entrance
┌──────────────────┐ ┌──────────────────┐
│ Keyed Wristband │ ◄─── Checked in 28 nanoseconds │ Origin Server │ ◄─── Untouched & Relaxed
│ (Session Token) │ Free to browse any page │ │ Zero database strain
└──────────────────┘ └──────────────────┘
When a browser first visits your website, Sibuna asks it to turn a smoothly balanced revolving door—solving a small mathematical puzzle in the background via WebAssembly in a fraction of a second.
Once through the door, Sibuna stamps the browser with a cryptographic wristband (a 16-byte keyed BLAKE3 session token).
For a human browsing a dozen pages, turning a revolving door once is completely imperceptible.
The burden is placed entirely on the abuser, while real people walk straight through.
The simplest topology. Sibuna receives public traffic on port 8080, validates requests, and forwards admitted traffic to your application on port 3000:
./zig-out/bin/sibuna --port 8080 --upstream-host 127.0.0.1 --upstream-port 3000
If you use Caddy for automatic TLS certificates, run Sibuna alongside Caddy as an authorization gate:
# Caddyfile
example.com {
# Send verification subrequests to Sibuna
forward_auth 127.0.0.1:8080 {
uri /__sibuna/verify
copy_headers X-Sibuna-Session X-Sibuna-Action
}
# Route challenge assets directly to Sibuna
handle /__sibuna/* {
reverse_proxy 127.0.0.1:8080
}
# Proxy admitted traffic to your application
handle {
reverse_proxy 127.0.0.1:3000
}
}
Run Sibuna on private loopback:
./zig-out/bin/sibuna --mode forward_auth --host 127.0.0.1 --port 8080
# nginx.conf
server {
listen 443 ssl;
server_name example.com;
location / {
auth_request /__sibuna_auth;
auth_request_set $sibuna_token $upstream_http_x_sibuna_session;
proxy_set_header X-Sibuna-Session $sibuna_token;
proxy_pass http://127.0.0.1:3000;
}
location = /__sibuna_auth {
internal;
proxy_pass http://127.0.0.1:8080/__sibuna/verify;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URI $request_uri;
proxy_set_header X-Forwarded-Method $request_method;
}
location /__sibuna/ {
proxy_pass http://127.0.0.1:8080;
}
}
Validate your ingress integration with the included automated test harness:
python3 tools/ingress_e2e.py zig-out/bin/sibuna --caddy /path/to/caddy --nginx /path/to/nginx
| Flag | Default | Description |
|---|---|---|
--mode <mode> | reverse_proxy | reverse_proxy to forward to upstream, or forward_auth for ingress subrequests |
--port <port> | 8080 | TCP port to listen on for incoming traffic |
--upstream-host <host> | 127.0.0.1 | Upstream application hostname or IP address |
--upstream-port <port> | 3000 | Upstream application TCP port |
--algorithm <algo> | posw | Proof-of-work algorithm: posw (sequential work) or hashcash |
--difficulty <bits> | 16 | Difficulty bits (PoSW depth is calibrated to bits - 3) |
--token-scheme <scheme> | mac | Session token format: mac (16-byte BLAKE3) or ed25519 |
--gate / --shield | shield | Operational surface: Gate for pure admission; Shield adds WAF inspection |
--rate-limit <n> | 100 | Maximum burst requests allowed by GCRA rate limiter |
--rate-window <sec> | 10 | Rate limiter refill window duration in seconds |
--policy-file <path> | none | Path to declarative JSON security policy file |
--data-dir <path> | none | Enables embedded Zaxonlite storage for persistence and clustering |
--console <host:port> | none | Enables the web operator console on the specified address |
--workers <n> | CPU count | Number of acceptor threads (each connection runs on its own bounded thread) |
--max-connections <n> | 1024 | Maximum concurrent connections before returning 503 Service Unavailable |
policy.json){
"default_action": "CHALLENGE",
"waf": true,
"thresholds": { "challenge_at": 10, "deny_at": 40, "bits_step": 5 },
"ip_rules": {
"10.0.0.0/8": "ALLOW",
"192.168.1.0/24": "ALLOW",
"2001:db8::/32": "DENY"
},
"rules": [
{
"name": "allow-internal-traffic",
"remote_addresses": ["10.0.0.0/8", "fd00::/8"],
"action": "ALLOW"
},
{
"name": "protect-checkout-endpoint",
"path": "/api/checkout/*",
"action": "CHALLENGE",
"challenge": { "difficulty": 20, "algorithm": "posw" }
},
{
"name": "block-forged-cloudflare-workers",
"headers": { "CF-Worker": ".*" },
"action": "DENY"
},
{
"name": "score-headless-browsers",
"user_agent": "Headless",
"action": "WEIGH",
"weight": 30
}
]
}
Modern web services face unprecedented scraping from AI training crawlers and automated LLM agents. Sibuna provides deep visibility and governance:
Verified: User-Agent matches provider signature and client IP resides within published subnets.Declared: Claims a crawler User-Agent from an unverified public IP.Suspected: Browser-like User-Agent exhibiting crawler heuristics (e.g. missing asset cascades).Human: Verified browser session that completed background proof-of-work.# 1. Bootstrap an administrator account while the daemon is stopped
./zig-out/bin/sibuna init-admin admin --data-dir ./data
# 2. Start Sibuna with storage and console listener enabled
./zig-out/bin/sibuna --data-dir ./data --console 127.0.0.1:19446
Open http://127.0.0.1:19446/console/ to access:
Sibuna's engineering design follows four foundational principles:
Adding moving parts increases the surface area for failure. Sibuna avoids external databases, cache servers, runtime interpreters, and container fleets. It compiles to a single, self-contained binary that does one job dependably.
Admission asks an unverified client to perform configurable work before accessing the origin, while Sibuna verifies the submitted proof natively. The cost depends on the algorithm, settings and client hardware. The benchmark records measure server operations under their stated conditions; they do not establish a universal energy or latency guarantee.
Request-path resources have explicit bounds:
A system must be honest about what it is, and what it is not.
Sibuna combines proof-of-work admission, bounded application inspection and an opt-in management console in one executable. Other projects cover different parts of that scope:
The book's empirical evaluation compares pinned, runnable products under documented workloads. Each result identifies its revision, configuration and host; memory and throughput figures describe those measurements.
Website · Book · Operations guide · Design discussions
For deep technical study, the repository includes two comprehensive publications:
The Sibuna Book (docs/book/):
A complete 13-chapter textbook covering the system from mathematical foundations through zero-allocation memory design, benchmarks, and production operations:
zig build book # Generates docs/build/sibuna-book.pdf
Shibuna Discussions (SID) (docs/sid/):
RFC-style architectural design records:
zig build sid # Compiles all SID specification papers to PDF
The engine is licensed under LGPL 3.0 and the console under AGPL 3.0,
including its WebAssembly interface. The default executable includes the console and is
distributed as a combined work under AGPL 3.0. Build the engine without the console using
-Dconsole=false.
See LICENSE for directory boundaries, LICENSES for the complete terms,
and NOTICE for dependencies. Corresponding source and build scripts are available
under each release tag; the console also provides a source-code link.
Companies seeking a version under terms other than LGPL or AGPL can contact the authors, Vikrant Rathore and Ronak Rathore, about alternative licensing. Libraries and other third-party materials remain subject to their respective licenses.
These projects overlap with different parts of Sibuna. Sibuna's bounded heuristic detectors do not implement ModSecurity's rule language or provide drop-in Core Rule Set compatibility.
Zig
77.4%
Python
11.6%
HTML
10.0%
Proof-of-work admission and a bounded web application firewall with an opt-in management console.
See the code
A simple and lightweight web application firewall to protect websites and APIs without CAPTCHAs.
Features • Quickstart • How It Works • Architecture • Deployment • Configuration • Philosophy • Documentation
sibuna is an open-source web application firewall (WAF) and anti-crawler daemon. It sits in front of your web application as a protective reverse proxy, or alongside your existing reverse proxy (such as Caddy, Nginx, or Traefik) as an authorization gate.
Instead of subjecting human visitors to frustrating image CAPTCHAs or privacy-invasive tracking scripts, Sibuna asks client browsers to solve a background computational puzzle whose cost depends on the configured difficulty and client hardware. Instead of requiring sprawling container clusters, external databases, or heavy interpreters, Sibuna runs as a single, self-contained executable with predictable, bounded memory.
Following the modular design of raylib, Sibuna is divided into small, single-purpose subsystems:
┌────────────────────────────────────────────────────────────────────────┐
│ SIBUNA SUBSYSTEMS │
├──────────────┬─────────────────────────────────────────────────────────┤
│ socket │ Native socket operations and interruption ownership │
│ net │ Zero-copy HTTP/1.1 stream parser & reverse proxy relay │
│ crypto │ Proof of Sequential Work (PoSW), Hashcash & BLAKE3 MAC │
│ policy │ Aho–Corasick signatures, Radix CIDR trie & semantic WAF │
│ challenge │ Stateless challenge coordinator & adaptive difficulty │
│ store │ 16-shard GCRA rate limiter & Robin Hood spent set │
│ edge │ Embedded Zaxonlite store (replicated SQLite Multi-Paxos)│
│ console │ WebAssembly operator UI, WebSocket telemetry & GeoIP │
└──────────────┴─────────────────────────────────────────────────────────┘
Sibuna provides two operational surfaces within the same executable:
┌─────────────────────────────────────────┐
│ Incoming Request │
└────────────────────┬────────────────────┘
│
[ Surface 1: Gate (--gate) ]
• Proof-of-work admission & sessions
• Bot signatures & Radix CIDR checks
• Atomic GCRA rate limiting & honeypots
│
▼ Admitted
[ Surface 2: Shield (--shield, default) ]
• Inline semantic attack inspection
• SQL injection & XSS automata
• Path traversal & shell execution filters
│
▼ Passed
┌─────────────────────────────────────────┐
│ Upstream Origin │
└─────────────────────────────────────────┘
Download a package from Releases, or build from source.
The v0.2.0 packages include the engine, embedded storage, browser solver and management console.
Clustering requires a separate -Dcluster=true source build with OpenSSL 3.
| Platform | Package | Requirements |
|---|---|---|
| Linux x86-64 | sibuna-linux-amd64.tar.gz | Linux 5.10 or later; statically linked musl |
| Linux ARM64 | sibuna-linux-arm64.tar.gz | Linux 5.10 or later; statically linked musl |
| macOS Apple Silicon | sibuna-macos-arm64.tar.gz | macOS 15 or later |
| macOS Intel | sibuna-macos-amd64.tar.gz | macOS 15 or later |
| Windows x86-64 | sibuna-windows-amd64.zip | Windows 10 / Server 2019 or later; native sibuna.exe |
macOS builds are unsigned. Packages include license texts, corresponding-source links and a
sibuna.build.json manifest. Verify the archive against the release's SHA256SUMS before use.
On Windows, extract the ZIP and run .\sibuna.exe --help from PowerShell. Use Ctrl+C for
ordered shutdown and restrict seed, credential and data files with Windows ACLs.
For Linux x86-64:
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/sibuna-linux-amd64.tar.gz
curl -fLO https://github.com/insanai/sibuna/releases/download/v0.2.0/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
tar -xzf sibuna-linux-amd64.tar.gz
(umask 077; openssl rand -hex 32 > sibuna.seed)
./sibuna --version
./sibuna --host 127.0.0.1 --port 8080 --upstream-port 3000 --secret-file ./sibuna.seed
Terminate public HTTPS at your ingress and keep Sibuna's listener private; see deployment limits and the operations guide.
Use Zig 0.17.0, the checksum-pinned release toolchain. The storage libraries include
reviewable compatibility sources in vendor/; original release digests are recorded there.
# Clone the repository
git clone https://github.com/insanai/sibuna.git
cd sibuna
# Compile optimized release binary
python3 tools/prepare_build.py
zig build -Doptimize=fast
The resulting standalone binary is located at ./zig-out/bin/sibuna.
Point Sibuna to your existing web service (for example, a local server on port 3000):
./zig-out/bin/sibuna --port 8080 --upstream-port 3000 --secret-file /run/sibuna.seed
Open http://localhost:8080 in your browser. Your application is now protected.
Note on secrets: The seed file contains 32 raw bytes (or 64 hex characters) used to sign session tokens. You can also supply the seed via the SIBUNA_SECRET environment variable. If omitted, Sibuna generates a secure random seed at startup; sessions then expire when the process restarts.
Most web security today relies on interrogation: a security guard stops you at the doorway, holds up blurry photos, and demands that you identify every traffic light before you are allowed in. It treats every human customer like a suspected intruder, frustrates real people, and tracks their identity across the internet.
Sibuna replaces the interrogation room with a simple physical principle: a revolving door and a wristband.
[ Real Human Visitor ] [ Automated Botnet / Scraper ]
│ │
│ Walks in normally │ Tries to force 50,000 requests/sec
▼ ▼
┌──────────────────┐ ┌──────────────────┐
│ Revolving Door │ ◄─── Effortless push (100ms) │ Revolving Door │ ◄─── Impossible resistance
│ (Proof of Work) │ Handled silently in background │ (Proof of Work) │ Attacker's CPU burns out
└────────┬─────────┘ └────────┬─────────┘
│ │
▼ Receives Wristband ▼ Blocked at the entrance
┌──────────────────┐ ┌──────────────────┐
│ Keyed Wristband │ ◄─── Checked in 28 nanoseconds │ Origin Server │ ◄─── Untouched & Relaxed
│ (Session Token) │ Free to browse any page │ │ Zero database strain
└──────────────────┘ └──────────────────┘
When a browser first visits your website, Sibuna asks it to turn a smoothly balanced revolving door—solving a small mathematical puzzle in the background via WebAssembly in a fraction of a second.
Once through the door, Sibuna stamps the browser with a cryptographic wristband (a 16-byte keyed BLAKE3 session token).
For a human browsing a dozen pages, turning a revolving door once is completely imperceptible.
The burden is placed entirely on the abuser, while real people walk straight through.
The simplest topology. Sibuna receives public traffic on port 8080, validates requests, and forwards admitted traffic to your application on port 3000:
./zig-out/bin/sibuna --port 8080 --upstream-host 127.0.0.1 --upstream-port 3000
If you use Caddy for automatic TLS certificates, run Sibuna alongside Caddy as an authorization gate:
# Caddyfile
example.com {
# Send verification subrequests to Sibuna
forward_auth 127.0.0.1:8080 {
uri /__sibuna/verify
copy_headers X-Sibuna-Session X-Sibuna-Action
}
# Route challenge assets directly to Sibuna
handle /__sibuna/* {
reverse_proxy 127.0.0.1:8080
}
# Proxy admitted traffic to your application
handle {
reverse_proxy 127.0.0.1:3000
}
}
Run Sibuna on private loopback:
./zig-out/bin/sibuna --mode forward_auth --host 127.0.0.1 --port 8080
# nginx.conf
server {
listen 443 ssl;
server_name example.com;
location / {
auth_request /__sibuna_auth;
auth_request_set $sibuna_token $upstream_http_x_sibuna_session;
proxy_set_header X-Sibuna-Session $sibuna_token;
proxy_pass http://127.0.0.1:3000;
}
location = /__sibuna_auth {
internal;
proxy_pass http://127.0.0.1:8080/__sibuna/verify;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Original-URI $request_uri;
proxy_set_header X-Forwarded-Method $request_method;
}
location /__sibuna/ {
proxy_pass http://127.0.0.1:8080;
}
}
Validate your ingress integration with the included automated test harness:
python3 tools/ingress_e2e.py zig-out/bin/sibuna --caddy /path/to/caddy --nginx /path/to/nginx
| Flag | Default | Description |
|---|---|---|
--mode <mode> | reverse_proxy | reverse_proxy to forward to upstream, or forward_auth for ingress subrequests |
--port <port> | 8080 | TCP port to listen on for incoming traffic |
--upstream-host <host> | 127.0.0.1 | Upstream application hostname or IP address |
--upstream-port <port> | 3000 | Upstream application TCP port |
--algorithm <algo> | posw | Proof-of-work algorithm: posw (sequential work) or hashcash |
--difficulty <bits> | 16 | Difficulty bits (PoSW depth is calibrated to bits - 3) |
--token-scheme <scheme> | mac | Session token format: mac (16-byte BLAKE3) or ed25519 |
--gate / --shield | shield | Operational surface: Gate for pure admission; Shield adds WAF inspection |
--rate-limit <n> | 100 | Maximum burst requests allowed by GCRA rate limiter |
--rate-window <sec> | 10 | Rate limiter refill window duration in seconds |
--policy-file <path> | none | Path to declarative JSON security policy file |
--data-dir <path> | none | Enables embedded Zaxonlite storage for persistence and clustering |
--console <host:port> | none | Enables the web operator console on the specified address |
--workers <n> | CPU count | Number of acceptor threads (each connection runs on its own bounded thread) |
--max-connections <n> | 1024 | Maximum concurrent connections before returning 503 Service Unavailable |
policy.json){
"default_action": "CHALLENGE",
"waf": true,
"thresholds": { "challenge_at": 10, "deny_at": 40, "bits_step": 5 },
"ip_rules": {
"10.0.0.0/8": "ALLOW",
"192.168.1.0/24": "ALLOW",
"2001:db8::/32": "DENY"
},
"rules": [
{
"name": "allow-internal-traffic",
"remote_addresses": ["10.0.0.0/8", "fd00::/8"],
"action": "ALLOW"
},
{
"name": "protect-checkout-endpoint",
"path": "/api/checkout/*",
"action": "CHALLENGE",
"challenge": { "difficulty": 20, "algorithm": "posw" }
},
{
"name": "block-forged-cloudflare-workers",
"headers": { "CF-Worker": ".*" },
"action": "DENY"
},
{
"name": "score-headless-browsers",
"user_agent": "Headless",
"action": "WEIGH",
"weight": 30
}
]
}
Modern web services face unprecedented scraping from AI training crawlers and automated LLM agents. Sibuna provides deep visibility and governance:
Verified: User-Agent matches provider signature and client IP resides within published subnets.Declared: Claims a crawler User-Agent from an unverified public IP.Suspected: Browser-like User-Agent exhibiting crawler heuristics (e.g. missing asset cascades).Human: Verified browser session that completed background proof-of-work.# 1. Bootstrap an administrator account while the daemon is stopped
./zig-out/bin/sibuna init-admin admin --data-dir ./data
# 2. Start Sibuna with storage and console listener enabled
./zig-out/bin/sibuna --data-dir ./data --console 127.0.0.1:19446
Open http://127.0.0.1:19446/console/ to access:
Sibuna's engineering design follows four foundational principles:
Adding moving parts increases the surface area for failure. Sibuna avoids external databases, cache servers, runtime interpreters, and container fleets. It compiles to a single, self-contained binary that does one job dependably.
Admission asks an unverified client to perform configurable work before accessing the origin, while Sibuna verifies the submitted proof natively. The cost depends on the algorithm, settings and client hardware. The benchmark records measure server operations under their stated conditions; they do not establish a universal energy or latency guarantee.
Request-path resources have explicit bounds:
A system must be honest about what it is, and what it is not.
Sibuna combines proof-of-work admission, bounded application inspection and an opt-in management console in one executable. Other projects cover different parts of that scope:
The book's empirical evaluation compares pinned, runnable products under documented workloads. Each result identifies its revision, configuration and host; memory and throughput figures describe those measurements.
Website · Book · Operations guide · Design discussions
For deep technical study, the repository includes two comprehensive publications:
The Sibuna Book (docs/book/):
A complete 13-chapter textbook covering the system from mathematical foundations through zero-allocation memory design, benchmarks, and production operations:
zig build book # Generates docs/build/sibuna-book.pdf
Shibuna Discussions (SID) (docs/sid/):
RFC-style architectural design records:
zig build sid # Compiles all SID specification papers to PDF
The engine is licensed under LGPL 3.0 and the console under AGPL 3.0,
including its WebAssembly interface. The default executable includes the console and is
distributed as a combined work under AGPL 3.0. Build the engine without the console using
-Dconsole=false.
See LICENSE for directory boundaries, LICENSES for the complete terms,
and NOTICE for dependencies. Corresponding source and build scripts are available
under each release tag; the console also provides a source-code link.
Companies seeking a version under terms other than LGPL or AGPL can contact the authors, Vikrant Rathore and Ronak Rathore, about alternative licensing. Libraries and other third-party materials remain subject to their respective licenses.
These projects overlap with different parts of Sibuna. Sibuna's bounded heuristic detectors do not implement ModSecurity's rule language or provide drop-in Core Rule Set compatibility.
Zig
77.4%
Python
11.6%
HTML
10.0%