Interactive self-hosted web security arcade and space defense simulator written in Rust.
Run the official zero-dependency container on port 4504:
docker run -d --name defend -p 4504:4504 -v /mnt/user/appdata/defend:/config ghcr.io/studio2201/defend:latestOpen your browser to http://localhost:4504 to start playing immediately.
On Debian, Ubuntu, Fedora, or RHEL:
curl -fsSL https://studio2201.github.io/packages/install.sh | sudo bashDeploy via the official Unraid Template:
- Copy
defend.xmlto your Unraid flash drive under/boot/config/plugins/dockerMan/templates-user/. - Open Docker -> Add Container -> Select defend from the template dropdown.
- Click Apply.
The backend service can be customized using the following environment variables:
| Variable | Description | Default |
|---|---|---|
PORT |
Network port the web server binds to | 4504 |
DEFEND_PIN |
Security PIN required for application access | (Disabled) |
DEFEND_DATA_DIR |
Directory path for persistent data and high scores | /config |
DEFEND_ALLOWED_ORIGINS |
CORS allowed origins list (comma-separated) | * |
TRUST_PROXY |
Honor reverse proxy headers (X-Forwarded-For) |
false |
TRUSTED_PROXY_IPS |
Comma-separated CIDR list of trusted reverse proxies | (None) |
LOG_LEVEL |
Tracing filter (error, warn, info, debug) |
info |
Every container and package includes a built-in administration utility (defend).
Launch interactive TUI dashboard:
docker exec -it defend defend tuiSystem diagnostics and self-healing check:
docker exec -it defend defend doctorCLI Command Reference:
defend tui— Interactive terminal user interface.defend doctor— Diagnoses storage permissions, ports, and database health.defend status— Displays network configuration and security parameters.defend data stats— Shows storage utilization and entry metrics.defend data list— Lists high scores and player leaderboard entries.
- Axum Web Backend: High-concurrency async HTTP runtime built on Tokio.
- Yew WebAssembly Frontend: Type-safe client bundle running natively in browser WASM runtime.
- Strict Input & Path Sanitization: Path canonicalization guards preventing directory traversal escapes.
- Fail-Closed Security PIN Authentication: Rate-limited brute force protection with automatic lockout timers.
Distributed under the Apache 2.0 License. See LICENSE for details.