5.6 KiB
Nginx L7 DDoS Protection! 💥 ⚡
- Debian 13 (trixie) and Ubuntu 26.04 LTS (raccoon) supported
- nginx 1.31.3
- HTTP/3 (QUIC) via AWS-LC
- ModSecurity v3 (libmodsecurity)
- Naxsi
- Lua (LuaJIT 2.1)
- Tenant Isolation.
- Cookie-based challenge
- Versions List
Debian 13 (trixie)
sudo install -d /etc/apt/keyrings
sudo curl -fsSL https://apt.julio.al/repository/public/keys/raweb.asc -o /etc/apt/keyrings/raweb.asc
echo "deb [signed-by=/etc/apt/keyrings/raweb.asc] https://apt.julio.al/repository/raweb-trixie trixie main" | sudo tee /etc/apt/sources.list.d/raweb.list
sudo apt update && sudo apt install twiy
Ubuntu 26.04 LTS (raccoon)
sudo install -d /etc/apt/keyrings
sudo curl -fsSL https://apt.julio.al/repository/public/keys/raweb.asc -o /etc/apt/keyrings/raweb.asc
echo "deb [signed-by=/etc/apt/keyrings/raweb.asc] https://apt.julio.al/repository/raweb-raccoon raccoon main" | sudo tee /etc/apt/sources.list.d/raweb.list
sudo apt update && sudo apt install twiy
Compile from source by yourself.
apt-get -y install git && cd /root/ && git clone https://git.julio.al/theraw/The-World-Is-Yours.git && cd The-World-Is-Yours/
# Debian 13
bash build/trixie.sh new
bash build/trixie.sh build
bash build/trixie.sh postfix
# Ubuntu 26.04 LTS
bash build/raccoon.sh new
bash build/raccoon.sh build
bash build/raccoon.sh postfix
To try a different upstream version, edit version and re-run new then build.
CLI Info
bash build/<distro>.sh new => Download all modules + nginx that are missing from /opt/.
(Re-run after changing the `version` file to fetch new versions.)
bash build/<distro>.sh build => Compile nginx. Re-runnable; will not touch your configs.
bash build/<distro>.sh postfix => Drop the default /nginx/nginx.conf, vhost, and systemd unit
into place. Run once on first install; re-running overwrites
/nginx/nginx.conf.
where <distro> is trixie or raccoon.
Nginx info.
=> Nginx Folder = /nginx/
=> --conf-path = /nginx/nginx.conf
=> --pid-path = /var/run/nginx.pid
=> --user = nginx
=> --group = nginx
=> --sbin-path = /usr/sbin/nginx
=> --error-log-path = /var/log/nginx/error.log
LUA RESTY CORE SCRIPTS = /usr/nginx_lua
Tenant Isolation
Confines each site's static file serving to its own root directory. A symlink, ..,
magic-link or cross-tenant path that escapes the site tree (e.g. a symlink to /etc/passwd)
is refused with 403, kernel-enforced via openat2(RESOLVE_BENEATH).
On by default, no vhost config needed. In-tree symlinks still work.
Where the config lives (nothing to add on a fresh install)
tenant_isolationis compiled default-on, so it applies to every site with no directive.- The
disable_symlinks if_not_owner from=$document_root;backstop ships in thehttp { }block of/nginx/nginx.conf, so every vhost inherits it. Do not add it per-site. - Your site configs live in
/nginx/live/*and inherit both layers automatically. - Upgrading an old install that kept its own
/nginx/nginx.conf? Add that onedisable_symlinksline to itshttp { }block once (or re-runpostfixto refresh the config).
Covered
- Static files served by nginx (the normal file path).
- Backstopped at the real serving
open()bydisable_symlinks if_not_owner, which also coversgzip_static,autoindex,dav,mp4/flv.
Not covered
- Dynamic content (PHP-FPM / NGINX Unit) is isolated separately per tenant (user / cgroup / namespace).
- Not fully race-free: a narrow probe->open timing window remains (closing it fully would
break
open_file_cache), so it is mitigated by thedisable_symlinksbackstop, not eliminated.
Optional per-vhost tuning
tenant_isolation off;turns it off for aserver/location.tenant_isolation_root /home/<user>;widens the confinement root to the tenant home (allows above-docroot in-tree symlinks, e.g. Laravel'sstorage).
How to install lua scripts
. /root/The-World-Is-Yours/version
cd /opt/mod/; git clone https://github.com/openresty/lua-resty-lrucache.git
cd /opt/mod/lua-resty-lrucache; make install PREFIX=${LUA_SCRIPTS}
nginx -s reload
Performance
vs. vanilla nginx (same version, default config)
| Area | Twiy | Vanilla nginx | Why |
|---|---|---|---|
| TLS handshake throughput | +5-15% | baseline | AWS-LC's tuned AES/ChaCha asm vs OpenSSL |
| WAF, Lua, HTTP/3 | included | not included | needs custom build |
Support options.
-
No free support for how to do things, please don't spam with questions in discord.
-
Free support for installation related errors only, is included.
-
Business inquiries, regarding anti-ddos protection or other security/optimization concerns you can contact me on : raw@dopehosting.net
Contributors
Feel free to submit a pull request. Special thanks to the following contributors:
|
ƬHE ЯAW ☣ |
Lục Thiên Phong |
