makit shield: a gate for web traffic, in front of every request.- Its own IP set (IP/CIDR with expiry, a hash table per prefix length — no ipset): ~180 ns per lookup with
1,000,000 entries; bulk lists (import, millions of entries); an allowlist that always wins. - Two independent switches: ask (Caddy
forward_auth/ nginxauth_requestcall/check;snippet caddy|nginx) and edge (makit in front: TLS via ACME TLS-ALPN, Cloudflare Origin Certificate or files; blocked
direct visitors dropped at accept;tcp://passthrough with optional PROXY v1). Modes block / observe / pass. - Cloudflare-aware:
CF-Connecting-IPtrusted only from Cloudflare ranges (refreshed daily). - HTTP rules (
security/http/): secret/admin probes, path traversal, scanners, React2Shell — automatic bans. - Request scoring (
security/scoring/http.yaml, online and overridable): probes, XSS in the URL, SQL injection,
Log4Shell, command injection, raw requests (RDP/TLS on the HTTP port), floods; values decoded first; per-IP
escalation and bursts; actions per level. Profiles (WordPress, PHP), overrides inshield.yaml,
makit shield customizefor your own copy in/etc/makit/security. - Bots, crawlers and AI agents (
security/bots/agents.yaml): search engines, AI search/assistants/crawlers/agents
(Web Bot Auth), SEO, link previews, monitors, libraries, headless browsers. Verified against published ranges or
forward-confirmed reverse DNS (fake Googlebots caught). Your policy per category or agent: allow, log, block,
ban,limit N/window(429). Bot score for undeclared automation. Your own bot IP sources: URLs refreshed on a
schedule, typed IPs (bots source add,bots ip add).bots robotswrites robots.txt lines. - Batch reports every 5 minutes (
report:): per suspicious IP with level, readable signals, paths, statuses and
the action taken; saved to/var/log/makit/shield/reports, sent throughmakit notifywhen worth it. - Sites: one server, many domains. The top of
shield.yamlis the global policy;sites:sets per-domain
mode, ban scope (server or site), allowlist, rules, scoring, bot policy, reports and notification channels —
site values override the global ones where both are set.ban/allow --site,makit shield sites,
check --host,report --site. makit shield analyze FILEscores nginx/Caddy access logs with the same policy (--follow --ban --notify).- Automatic bans apply at once and are saved in batches (no disk write in the request path); optional nftables
kernel set; request snapshots; lock-out guards for your SSH address and Cloudflare.
- Its own IP set (IP/CIDR with expiry, a hash table per prefix length — no ipset): ~180 ns per lookup with
makit notify: Telegram, Slack, Google Chat, Discord, Microsoft Teams, ntfy, webhooks, email; per-channel minimum
level, no duplicate floods. Scheduled scans and shield reports use it.makit top: Shield tab — ask and edge switches, mode, counters, bans, allowlist, bot IPs and sources with inline
inputs, latest reports. Setup moves to tab 8. A version line: green when up to date, yellow with the newer
release andmakit upgradewhen there is one.benchmark/: reproducible benchmarks (benchmark/run.sh, Docker only) — per-step decision cost and end-to-end
latency with and without makit. A browser request costs ~9 µs to decide; makit adds well under 1 ms (p50).- Catalog:
/etc/makit/securityfor your own files (never overwritten bymakit rules update). - Guides: docs/security/shield.md, bots.md, notifications.md. README leads with what makit is now.
curl -fsSL https://raw.githubusercontent.com/material-atomic/makit/v0.5.0/install.sh | bashSource tarball SHA256 (MAKIT_SHA256): 226e63c06db20509a798a7c5d0ff90a9bc9df176c57ba7216b46e64e585baa4c
Source tarball and makit-core binaries: SHA256SUMS (verified by install.sh).