
🛡️ オープンソースかつクラウドネイティブなWebアプリケーションファイアウォール(WAF)
<p align="center">
<img alt="BunkerWeb logo" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/misc/logo.png" height=100 width=350 />
</p>
<p align="center">
<img src="https://img.shields.io/github/v/release/bunkerity/bunkerweb?label=stable" />
<img src="https://img.shields.io/github/v/release/bunkerity/bunkerweb?include_prereleases&label=latest" />
<br />
<img src="https://img.shields.io/github/last-commit/bunkerity/bunkerweb" />
<img src="https://img.shields.io/github/issues/bunkerity/bunkerweb">
<img src="https://img.shields.io/github/issues-pr/bunkerity/bunkerweb">
<br />
<img src="https://img.shields.io/github/actions/workflow/status/bunkerity/bunkerweb/dev.yml?branch=dev&label=CI/CD%20dev" />
<img src="https://img.shields.io/github/actions/workflow/status/bunkerity/bunkerweb/staging.yml?branch=staging&label=CI/CD%20staging" />
<a href="https://github.com/bunkerity/bunkerweb/actions/workflows/release.yml"><img src="https://img.shields.io/github/actions/workflow/status/bunkerity/bunkerweb/release.yml?label=CI/CD%20release" alt="Release workflow status" /></a>
<br />
<a href="https://www.bestpractices.dev/projects/8001">
<img src="https://www.bestpractices.dev/projects/8001/badge">
</a>
<a href="https://gitrated.com/bunkerity/bunkerweb"><img src="https://gitrated.com/bunkerity/bunkerweb/badge" alt="GitRated rating" /></a>
<a href="https://score.getplumber.io/github.com/bunkerity/bunkerweb"><img src="https://score.getplumber.io/github.com/bunkerity/bunkerweb.svg" alt="Plumber CI/CD security score" /></a>
<br />
<a href="https://www.star-history.com/bunkerity/bunkerweb">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/badge?repo=bunkerity/bunkerweb&theme=dark" />
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/badge?repo=bunkerity/bunkerweb" />
<img alt="Star History Rank" src="https://api.star-history.com/badge?repo=bunkerity/bunkerweb" width=140 />
</picture>
</a>
</p>
<p align="center">
🌐 <a href="https://www.bunkerweb.io/?utm_campaign=self&utm_source=github">ウェブサイト</a>
|
🤝 <a href="https://panel.bunkerweb.io/?utm_campaign=self&utm_source=github">パネル</a>
|
📓 <a href="https://docs.bunkerweb.io/?utm_campaign=self&utm_source=github">ドキュメント</a>
|
👨💻 <a href="https://demo.bunkerweb.io/?utm_campaign=self&utm_source=github">デモ</a>
|
📱 <a href="https://demo-ui.bunkerweb.io/?utm_campaign=self&utm_source=github">デモ UI</a>
|
🧩 <a href="https://github.com/bunkerity/bunkerweb-templates">テンプレート</a>
|
🛡️ <a href="https://github.com/bunkerity/bunkerweb/raw/v1.6.15/examples">サンプル</a>
<br/>
💬 <a href="https://discord.com/invite/fTf46FmtyD">チャット</a>
|
📝 <a href="https://github.com/bunkerity/bunkerweb/discussions">フォーラム</a>
|
📝 <a href="https://community.bunkerweb.io/?utm_campaign=self&utm_source=github">コミュニティ</a>
|
🗺️ <a href="https://www.bunkerweb.io/threatmap/?utm_campaign=self&utm_source=github">脅威マップ</a>
|
📊 <a href="https://status.bunkerweb.io/?utm_campaign=self&utm_source=github">ステータス</a>
|
🔎 <a href="https://forms.gle/e3VgymAteYPnwM1j9">フィードバック</a>
</p>
> 🛡️ デフォルトでセキュアな世界をもう一度!
# BunkerWeb
<p align="center">
<img alt="Overview banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/intro-overview.svg" />
</p>
BunkerWeb は、次世代のオープンソース Web Application Firewall (WAF) です。
フル機能の Web サーバー(内部的には [NGINX](https://nginx.org/) をベースにしています)であり、Web サービスを「デフォルトでセキュア」にするために保護します。BunkerWeb は既存の環境([Linux](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#linux)、[Docker](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#docker)、[Swarm](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#swarm)、[Kubernetes](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#kubernetes) など)にリバースプロキシとしてシームレスに統合でき、完全に設定可能です(ご安心ください、CLI がお好みでなければ[素晴らしい Web UI](https://docs.bunkerweb.io/1.6.15/web-ui/?utm_campaign=self&utm_source=github) があります)。言い換えれば、サイバーセキュリティはもはや面倒なものではありません。
BunkerWeb は主要な[セキュリティ機能](https://docs.bunkerweb.io/1.6.15/advanced/?utm_campaign=self&utm_source=github#security-tuning)をコアの一部として備えていますが、[プラグインシステム](https://docs.bunkerweb.io/1.6.15/plugins/?utm_campaign=self&utm_source=github)によって追加機能で簡単に拡張できます。
## なぜ BunkerWeb なのか?
https://github.com/user-attachments/assets/c3fed740-28d8-4335-ab05-113a9e815b4f
- **既存環境への簡単な統合**: BunkerWeb を Linux、Docker、Swarm、Kubernetes などのさまざまな環境にシームレスに統合できます。スムーズな移行と手間のかからない導入を実現します。
- **高いカスタマイズ性**: 特定の要件に合わせて BunkerWeb を簡単に調整できます。機能の有効化、無効化、設定を手間なく行えるため、独自のユースケースに応じてセキュリティ設定をカスタマイズできます。
- **デフォルトでセキュア**: BunkerWeb は、Web サービスにすぐに使える手間のかからない最小限のセキュリティを提供します。最初から安心と強化された保護を体験できます。
- **素晴らしい Web UI**: 優れた Web ユーザーインターフェース (UI) により、BunkerWeb をより効率的に管理できます。ユーザーフレンドリーなグラフィカルインターフェースを通じて設定を簡単に操作でき、コマンドラインインターフェース (CLI) は不要です。
- **プラグインシステム**: 独自のユースケースに合わせて BunkerWeb の機能を拡張できます。追加のセキュリティ対策をシームレスに統合し、特定の要件に応じて BunkerWeb の機能をカスタマイズできます。
- **「自由」としての無料**: BunkerWeb は自由でオープンな [AGPLv3 ライセンス](https://www.gnu.org/licenses/agpl-3.0.en.html)の下でライセンスされており、自由と開放性の原則を採用しています。コミュニティのサポートのもと、ソフトウェアを使用、変更、配布する自由を享受できます。
- **プロフェッショナルサービス**: BunkerWeb のメンテナーから直接、技術サポート、カスタマイズされたコンサルティング、カスタム開発を受けることができます。詳細については [Bunker Panel](https://panel.bunkerweb.io/?utm_campaign=self&utm_source=github) をご覧ください。
## セキュリティ機能
セキュリティ機能の非網羅的なリスト:
- 透過的な **Let's Encrypt** 自動化による **HTTPS** サポート
- **最先端の Web セキュリティ**: HTTP セキュリティヘッダー、情報漏洩の防止、TLS 強化など
- **OWASP Core Rule Set** を備えた統合 **ModSecurity WAF**
- HTTP ステータスコードに基づく異常な動作の**自動禁止**
- クライアントに対する**接続とリクエストの制限**の適用
- **チャレンジ**(Cookie、JavaScript、captcha、hCaptcha、reCAPTCHA など)を解くよう求めることで**ボットをブロック**
- 外部ブラックリストと DNSBL による**既知の悪意ある IP のブロック**
- その他多数...
コアセキュリティ機能の詳細については、ドキュメントの[セキュリティチューニング](https://docs.bunkerweb.io/1.6.15/advanced/?utm_campaign=self&utm_source=github#security-tuning)セクションをご覧ください。
## デモ
https://github.com/user-attachments/assets/6fc0e3c1-d353-4a84-bad0-15bf9b6623a5
BunkerWeb で保護されたデモ Web サイトは [demo.bunkerweb.io](https://demo.bunkerweb.io/?utm_campaign=self&utm_source=github) で利用できます。ぜひ訪問して、いくつかのセキュリティテストを実行してみてください。
## Web UI
https://github.com/user-attachments/assets/a3ed56f8-c124-4ca9-b8b3-4be0913b3078
BunkerWeb は、インスタンスとその設定を管理するためのオプションの[ユーザーインターフェース](https://github.com/bunkerity/bunkerweb/blob/master/web-ui.md)を提供しています。オンラインの読み取り専用デモは [demo-ui.bunkerweb.io](https://demo-ui.bunkerweb.io/?utm_campaign=self&utm_source=doc) で利用できます。ぜひご自身でお試しください。
## BunkerWeb Cloud
自身で BunkerWeb インスタンスをセルフホストして管理したくない場合は、BunkerWeb 向けのフルマネージド SaaS サービスである BunkerWeb Cloud にご興味があるかもしれません。
[BunkerWeb Cloud インスタンス](https://panel.bunkerweb.io/store/bunkerweb-cloud?utm_campaign=self&utm_source=doc)を注文すると、以下にアクセスできます:
- 当社のクラウドでホストされるフルマネージドの BunkerWeb インスタンス
- PRO 機能を含むすべての BunkerWeb 機能
- ダッシュボードとアラートを備えた監視プラットフォーム
- 設定を支援する技術サポート
BunkerWeb Cloud の提供にご興味がある場合は、お気軽に[お問い合わせ](https://panel.bunkerweb.io/contact.php?utm_campaign=self&utm_source=doc)ください。お客様のニーズについてご相談させていただきます。
## PRO バージョン
[BunkerWeb パネル](https://panel.bunkerweb.io/store/bunkerweb-pro?utm_campaign=self&utm_source=doc)から 30 日間の BunkerWeb PRO 無料トライアルを開始できます。
BunkerWeb を使用する際には、オープンソース版または PRO 版のどちらを使用するかを選択できます。
強化されたセキュリティ、豊かなユーザー体験、技術的な監視など、BunkerWeb PRO 版では BunkerWeb を最大限に活用し、プロフェッショナルなニーズを満たすことができます。
ドキュメントやユーザーインターフェースでは、PRO 機能は王冠 <img src="https://docs.bunkerweb.io/1.6.15/assets/img/pro-icon.svg" alt="crown pro icon" height="32px" width="32px"> で注釈され、オープンソース版に統合されたものと区別されています。
オープンソース版から PRO 版へは、いつでも簡単にアップグレードできます。手順は簡単です:
- [30 日間の BunkerWeb PRO 無料トライアル](https://panel.bunkerweb.io/store/bunkerweb-pro?utm_campaign=self&utm_source=doc)を開始する
- クライアントエリアに接続したら、PRO ライセンスキーをコピーする
- [Web UI](https://docs.bunkerweb.io/1.6.15/web-ui/#upgrade-to-pro) または[特定の設定](https://docs.bunkerweb.io/1.6.15/features/#pro)を使用して、ライセンスキーを BunkerWeb に貼り付ける
PRO 版に関してご質問がある場合は、お気軽に [BunkerWeb パネル](https://panel.bunkerweb.io/knowledgebase?utm_campaign=self&utm_source=doc)をご覧いただくか、[お問い合わせ](https://panel.bunkerweb.io/contact.php?utm_campaign=self&utm_source=doc)ください。
## プロフェッショナルサービス
プロジェクトのメンテナーから直接プロフェッショナルサービスを受けることで、BunkerWeb を最大限に活用できます。技術サポートからカスタマイズされたコンサルティングや開発まで、お客様の Web サービスのセキュリティを支援します。
詳細については、プロフェッショナルサービス専用のプラットフォームである [BunkerWeb パネル](https://panel.bunkerweb.io/?utm_campaign=self&utm_source=doc)をご覧ください。
ご質問がある場合は、お気軽に[お問い合わせ](https://panel.bunkerweb.io/contact.php?utm_campaign=self&utm_source=doc)ください。お客様のニーズにお応えできることを嬉しく思います。
## エコシステム、コミュニティ、リソース
BunkerWeb に関する公式ウェブサイト、ツール、リソース:
- [**ウェブサイト**](https://www.bunkerweb.io/?utm_campaign=self&utm_source=doc): BunkerWeb に関する詳細情報、ニュース、記事を入手できます
- [**パネル**](https://panel.bunkerweb.io/?utm_campaign=self&utm_source=doc): BunkerWeb に関するプロフェッショナルサービス(技術サポートなど)を注文・管理するための専用プラットフォーム
- [**ドキュメント**](https://docs.bunkerweb.io): BunkerWeb ソリューションの技術ドキュメント
- [**デモ**](https://demo.bunkerweb.io/?utm_campaign=self&utm_source=doc): BunkerWeb のデモンストレーション Web サイト。ソリューションの堅牢性をテストするために、ぜひ攻撃を試みてください
- [**Web UI**](https://demo-ui.bunkerweb.io/?utm_campaign=self&utm_source=doc): BunkerWeb の Web UI のオンライン読み取り専用デモ
- [**脅威マップ**](https://www.bunkerweb.io/threatmap/?utm_campaign=self&utm_source=doc): 世界中の BunkerWeb インスタンスによってブロックされたサイバー攻撃のライブ表示
コミュニティとソーシャルネットワーク:
- [**Discord**](https://discord.com/invite/fTf46FmtyD)
- [**LinkedIn**](https://www.linkedin.com/company/bunkerity/)
- [**Twitter**](https://twitter.com/bunkerity)
- [**Reddit**](https://www.reddit.com/r/BunkerWeb/)
# コンセプト
<p align="center">
<img alt="Concepts banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/concepts.svg" />
</p>
BunkerWeb の主要なコンセプトの詳細については、[ドキュメント](https://docs.bunkerweb.io/1.6.15/concepts/?utm_campaign=self&utm_source=github)をご覧ください。
## 統合
最初のコンセプトは、BunkerWeb のターゲット環境への統合です。BunkerWeb の目標の 1 つは既存環境にシームレスに統合することであるため、「インストール」ではなく「統合」という言葉を使用することを好みます。
以下の統合が公式にサポートされています:
- [Docker](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#docker)
- [Linux](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#linux)
- [Docker autoconf](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#docker-autoconf)
- [Kubernetes](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#kubernetes)
- [Swarm](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#swarm)
- [Microsoft Azure](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#microsoft-azure)
## 設定
BunkerWeb を環境に統合したら、Web アプリケーションを提供し保護するために設定する必要があります。
BunkerWeb の設定は、私たちが「設定」または「変数」と呼ぶものを使用して行います。各設定は `AUTO_LETS_ENCRYPT` や `USE_ANTIBOT` などの名前で識別されます。設定に値を割り当てて BunkerWeb を構成できます。
以下は BunkerWeb 設定のダミー例です:```conf
SERVER_NAME=www.example.com
AUTO_LETS_ENCRYPT=yes
USE_ANTIBOT=captcha
REFERRER_POLICY=no-referrer
USE_MODSECURITY=no
USE_GZIP=yes
USE_BROTLI=no
```
## マルチサイトモード
マルチサイトモードは、BunkerWeb を使用する際に理解しておくべき重要な概念です。目的は Web アプリケーションを保護することであるため、私たちは本質的に「バーチャルホスト」または「vhost」という概念を継承しています(詳細は[こちら](https://en.wikipedia.org/wiki/Virtual_hosting))。これにより、単一の(またはクラスターの)インスタンスから複数の Web アプリケーションを配信することが可能になります。
デフォルトでは、BunkerWeb のマルチサイトモードは無効になっており、1 つの Web アプリケーションのみが配信され、すべての設定がそれに適用されます。典型的なユースケースは、保護するアプリケーションが 1 つだけの場合です。その場合はマルチサイトを気にする必要はなく、デフォルトの動作が適切です。
マルチサイトモードが有効になると、BunkerWeb は複数の Web アプリケーションを配信および保護します。各 Web アプリケーションは一意のサーバー名で識別され、独自の設定セットを持ちます。典型的なユースケースは、保護するアプリケーションが複数あり、単一の(または統合方法に応じてクラスターの)BunkerWeb インスタンスを使用したい場合です。
## カスタム設定
設定のみですべてのユースケースを満たすことは不可能であるため([外部プラグイン](https://docs.bunkerweb.io/1.6.15/plugins/?utm_campaign=self&utm_source=github)を使用しても同様です)、特定の課題を解決するためにカスタム設定を使用できます。
内部的には、BunkerWeb は有名な NGINX Web サーバーを使用しているため、特定のニーズに合わせてその設定システムを活用できます。カスタム NGINX 設定は、HTTP やサーバー(すべてのサーバーおよび/または特定のサーバーブロック)など、さまざまな[コンテキスト](https://docs.nginx.com/nginx/admin-guide/basic-functionality/managing-configuration-files/#contexts)に含めることができます。
BunkerWeb のもう 1 つのコアコンポーネントは ModSecurity Web Application Firewall です。カスタム設定を使用して、誤検知を修正したり、カスタムルールを追加したりすることもできます。
## データベース
<p align="center">
<img alt="Database model" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/bunkerweb_db.svg" />
</p>
BunkerWeb の現在の設定状態は、以下のデータを含むバックエンドデータベースに保存されます:
- すべてのサービスに対して定義された設定
- カスタム設定
- BunkerWeb インスタンス
- ジョブ実行に関するメタデータ
- キャッシュされたファイル
以下のバックエンドデータベースがサポートされています:SQLite、MariaDB、MySQL、PostgreSQL。
## スケジューラー
すべてを自動的に連携させるために、スケジューラーと呼ばれる専用サービスが以下の役割を担います:
- 設定とカスタム設定をデータベース内に保存する
- さまざまなタスク(ジョブと呼ばれる)を実行する
- BunkerWeb が理解できる設定を生成する
- 他のサービス(Web UI や autoconf など)の仲介役となる
言い換えれば、スケジューラーは BunkerWeb の頭脳です。
# セットアップ
コンテナイメージや Linux パッケージをソースからビルドしますか?[コミュニティビルドガイド](https://github.com/bunkerity/bunkerweb/blob/master/docs/building.md)を参照してください。
<!--## BunkerWeb Cloud
<p align="center">
<img alt="Docker banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/bunkerweb-cloud.webp" />
</p>
BunkerWeb Cloud は、BunkerWeb を始めるための最も簡単な方法です。手間のかからない完全マネージドの BunkerWeb サービスを提供します。BunkerWeb-as-a-Service のようなものだと考えてください!
BunkerWeb Cloud ベータ版の詳細については[こちら](https://www.bunkerweb.io/saas-offer-cloud/?utm_campaign=self&utm_source=docs)をご覧ください。[BunkerWeb パネル](https://panel.bunkerweb.io/store/bunkerweb-cloud?utm_campaign=self&utm_source=docs)から無料で申し込むことができます。
-->
## Linux
<p align="center">
<img alt="Linux banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/integration-linux.svg" />
</p>
サポートされている Linux ディストリビューションのリスト:
- Debian 12 "Bookworm"
- Debian 13 "Trixie"
- Ubuntu 22.04 "Jammy"
- Ubuntu 24.04 "Noble"
- Ubuntu 26.04 "Resolute Raccoon"
- Fedora 43
- Fedora 44
- RHEL、CentOS、Rocky Linux、AlmaLinux 8、9、10
詳細については、ドキュメントの [Linux セクション](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#linux)をご覧ください。
## Docker
<p align="center">
<img alt="Docker banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/integration-docker.svg" />
</p>
x64、x86、armv7、arm64 プラットフォーム向けのすぐに使えるビルド済みイメージを [Docker Hub](https://hub.docker.com/u/bunkerity) で提供しています。
Docker 統合の主要な概念は以下のとおりです:
- BunkerWeb を設定するための**環境変数**
- 設定を保存しジョブを実行する**スケジューラー**コンテナ
- クライアント向けにポートを公開し、アップストリームの Web サービスに接続するための**ネットワーク**
詳細については、ドキュメントの [Docker 統合セクション](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#docker)をご覧ください。
## Docker autoconf
<p align="center">
<img alt="Docker autoconf banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/integration-autoconf.svg" />
</p>
環境変数を使用する欠点は、更新があるたびにコンテナを再作成する必要があり、あまり便利ではないことです。この問題に対処するために、**autoconf** と呼ばれる別のイメージを使用できます。これは Docker イベントを監視し、コンテナを再作成することなく BunkerWeb をリアルタイムで自動的に再設定します。
BunkerWeb コンテナに環境変数を定義する代わりに、Web アプリケーションコンテナに**ラベル**を追加するだけで、**autoconf** が残りの処理を「自動的に」行います。
詳細については、ドキュメントの [Docker autoconf セクション](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#docker-autoconf)をご覧ください。
## Kubernetes
<p align="center">
<img alt="Kubernetes banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/integration-kubernetes.svg" />
</p>
autoconf は [Ingress コントローラー](https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/)として機能し、[Ingress リソース](https://kubernetes.io/docs/concepts/services-networking/ingress/)に従って BunkerWeb インスタンスを設定します。また、カスタム設定用の [ConfigMap](https://kubernetes.io/docs/concepts/configuration/configmap/) など、他の Kubernetes オブジェクトも監視します。
BunkerWeb の公式 [Helm チャート](https://helm.sh/)は [bunkerity/bunkerweb-helm リポジトリ](https://github.com/bunkerity/bunkerweb-helm)で入手できます。
詳細については、ドキュメントの [Kubernetes セクション](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#kubernetes)をご覧ください。
## Microsoft Azure
<p align="center">
<img alt="Azure banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/integration-azure.webp" />
</p>
BunkerWeb は [Azure Marketplace](https://azuremarketplace.microsoft.com/fr-fr/marketplace/apps/bunkerity.bunkerweb?tab=Overview) に掲載されており、ARM テンプレートは [misc フォルダー](https://github.com/bunkerity/bunkerweb/raw/v1.6.15/misc/integrations/azure-arm-template.json)で入手できます。
詳細については、ドキュメントの [Microsoft Azure セクション](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#microsoft-azure)をご覧ください。
## Swarm
<p align="center">
<img alt="Swarm banner" src="https://raw.githubusercontent.com/bunkerity/bunkerweb/v1.6.15/docs/assets/img/integration-swarm.svg" />
</p>
BunkerWeb インスタンスを自動的に設定するために、**autoconf** と呼ばれる特別なサービスが、サービスの作成や削除などの Docker Swarm イベントを監視し、ダウンタイムなしで **BunkerWeb インスタンス**をリアルタイムで自動的に設定します。
[Docker autoconf 統合](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#docker-autoconf)と同様に、Web サービスの設定は特別な **bunkerweb.** プレフィックスで始まるラベルを使用して定義されます。
詳細については、ドキュメントの [Swarm セクション](https://docs.bunkerweb.io/1.6.15/integrations/?utm_campaign=self&utm_source=github#swarm)をご覧ください。
# クイックスタートガイド
お好みの統合方法で BunkerWeb をセットアップしたら、[クイックスタートガイド](https://docs.bunkerweb.io/1.6.15/quickstart-guide/?utm_campaign=self&utm_source=github)に従ってください。Web サービスを保護するためのインストールと最初の設定について説明しています。
# セキュリティチューニング
BunkerWeb は、[機能](https://docs.bunkerweb.io/1.6.15/features/?utm_campaign=self&utm_source=github)で設定できる多くのセキュリティ機能を提供しています。設定のデフォルト値は最小限の「デフォルトでのセキュリティ」を保証しますが、それらをチューニングすることを強くお勧めします。そうすることで、希望するセキュリティレベルを確保できるだけでなく、誤検知も管理できます。
詳細については、ドキュメントの[セキュリティチューニングセクション](https://docs.bunkerweb.io/1.6.15/advanced/?utm_campaign=self&utm_source=github#security-tuning)をご覧ください。
# 設定
一般的なルールとして、マルチサイトモードが有効な場合、マルチサイトコンテキストの設定を特定のサーバーに適用したいときは、例えば `www.example.com_USE_ANTIBOT=captcha` や `myapp.example.com_USE_GZIP=yes` のように、プライマリ(最初の)サーバー名をプレフィックスとして追加する必要があります。
設定が「複数」と見なされる場合、例えば `REVERSE_PROXY_URL_1=/subdir`、`REVERSE_PROXY_HOST_1=http://myhost1`、`REVERSE_PROXY_URL_2=/anotherdir`、`REVERSE_PROXY_HOST_2=http://myhost2` のように、サフィックスとして番号を追加することで、同じ機能に対して複数の設定グループを持つことができます。
完全なリストについては、ドキュメントの[機能セクション](https://docs.bunkerweb.io/1.6.15/features/?utm_campaign=self&utm_source=github)をご確認ください。
# Web UI
https://github.com/user-attachments/assets/a3ed56f8-c124-4ca9-b8b3-4be0913b3078
「Web UI」は、コマンドラインの代わりにユーザーフレンドリーなインターフェースを使用して BunkerWeb インスタンスを管理するのに役立つ Web アプリケーションです。
Web UI が提供する機能のリストは以下のとおりです:
- ブロックされた攻撃の包括的な表示
- BunkerWeb インスタンスの起動、停止、再起動、リロード
- Web アプリケーションの設定の追加、編集、削除
- NGINX および ModSecurity のカスタム設定の追加、編集、削除
- 外部プラグインのインストールとアンインストール
- キャッシュされたファイルの探索
- ジョブ実行の監視と必要に応じた再起動
- ログの表示とパターンの検索
詳細については、ドキュメントの [Web UI セクション](https://docs.bunkerweb.io/1.6.15/web-ui/?utm_campaign=self&utm_source=github)をご覧ください。
# プラグイン
BunkerWeb には、新しい機能を簡単に追加できるようにするプラグインシステムが付属しています。プラグインがインストールされると、プラグインによって定義された追加の設定を使用して管理できます。
以下は、私たちがメンテナンスしている「公式」プラグインのリストです(詳細については [bunkerweb-plugins](https://github.com/bunkerity/bunkerweb-plugins/?utm_campaign=self&utm_source=github) リポジトリをご覧ください):
| Name | Version | Description | Link |
| :------------: | :-----: | :------------------------------------------------------------------------------------------------------------------------------- | :-------------------------------------------------------------------------------------------------: |
| **ClamAV** | 1.9 | ClamAV アンチウイルスエンジンでアップロードされたファイルを自動的にスキャンし、ファイルが悪意のあるものとして検出された場合にリクエストを拒否します。 | [bunkerweb-plugins/clamav](https://github.com/bunkerity/bunkerweb-plugins/tree/main/clamav) |
| **Coraza** | 1.9 | Coraza WAF(ModSecurity の代替)を使用してリクエストを検査します。 | [bunkerweb-plugins/coraza](https://github.com/bunkerity/bunkerweb-plugins/tree/main/coraza) |
| **Discord** | 1.9 | Webhook を使用して Discord チャンネルにセキュリティ通知を送信します。 | [bunkerweb-plugins/discord](https://github.com/bunkerity/bunkerweb-plugins/tree/main/discord) |
| **Slack** | 1.9 | Webhook を使用して Slack チャンネルにセキュリティ通知を送信します。 | [bunkerweb-plugins/slack](https://github.com/bunkerity/bunkerweb-plugins/tree/main/slack) |
| **VirusTotal** | 1.9 | VirusTotal API でアップロードされたファイルを自動的にスキャンし、ファイルが悪意のあるものとして検出された場合にリクエストを拒否します。 | [bunkerweb-plugins/virustotal](https://github.com/bunkerity/bunkerweb-plugins/tree/main/virustotal) |
| **WebHook** | 1.9 | Webhook を使用してカスタム HTTP エンドポイントにセキュリティ通知を送信します。 | [bunkerweb-plugins/webhook](https://github.com/bunkerity/bunkerweb-plugins/tree/main/webhook) |
詳細については、ドキュメントの[プラグインセクション](https://docs.bunkerweb.io/1.6.15/plugins/?utm_campaign=self&utm_source=github)をご覧ください。
# 言語サポートとローカライゼーション
BunkerWeb UI は複数の言語をサポートしています。翻訳は `src/ui/app/static/locales` ディレクトリで管理されています。現在、以下の言語が利用可能です:
- アラビア語 (ar)
- ベンガル語 (bn)
- ブラジルポルトガル語 (br)
- ドイツ語 (de)
- 英語 (en)
- スペイン語 (es)
- フランス語 (fr)
- ヒンディー語 (hi)
- イタリア語 (it)
- 韓国語 (ko)
- ポーランド語 (pl)
- ポルトガル語 (pt)
- ロシア語 (ru)
- トルコ語 (tr)
- 繁体字中国語 (tw)
- ウルドゥー語 (ur)
- 簡体字中国語 (zh)
翻訳の出所とレビューステータスの詳細については、[locales/README.md](https://github.com/bunkerity/bunkerweb/raw/v1.6.15/src/ui/app/static/locales/README.md) をご覧ください。
## 翻訳への貢献
ロケールファイルの改善や新しいロケールファイルの追加への貢献を歓迎します!
**翻訳を貢献する方法:**
1. `src/ui/app/lang_config.py` ファイルを編集して、あなたの言語(コード、名前、フラグ、english_name)を追加します。
2. `en.json` をテンプレートとして `src/ui/app/static/locales/` にコピーし、あなたの言語コード(例:ドイツ語の場合は `de.json`)に名前を変更します。
3. 新しいファイル内の値を翻訳します。
4. `locales/README.md` の表を更新して、あなたの言語を追加し、作成者/レビュー者を示します。
5. プルリクエストを送信します。
更新の場合は、該当するファイルを編集し、必要に応じて出所の表を更新してください。
完全なガイドラインについては、[locales/README.md](https://github.com/bunkerity/bunkerweb/raw/v1.6.15/src/ui/app/static/locales/README.md) をご覧ください。
# サポート
## プロフェッショナル
BunkerWeb のメンテナーから直接テクニカルサポートを受けることができます。詳細については、プロフェッショナルサービス専用のプラットフォームである [BunkerWeb パネル](https://panel.bunkerweb.io/?utm_campaign=self&utm_source=github)をご覧ください。
ご質問がある場合は、お気軽に[お問い合わせ](https://panel.bunkerweb.io/contact.php?utm_campaign=self&utm_source=github)ください。お客様のニーズにお応えできることを嬉しく思います。
## コミュニティ
無料のコミュニティサポートを受けるには、以下のメディアをご利用いただけます:
- [Discord サーバー](https://discord.com/invite/fTf46FmtyD)の BunkerWeb の #help チャンネル
- [GitHub discussions](https://github.com/bunkerity/bunkerweb/discussions) の help カテゴリ
- [/r/BunkerWeb](https://www.reddit.com/r/BunkerWeb) サブレディット
- [Server Fault](https://serverfault.com/) および [Super User](https://superuser.com/) フォーラム
ヘルプを求めるために [GitHub issues](https://github.com/bunkerity/bunkerweb/issues) を使用しないでください。バグ報告と機能リクエストにのみ使用してください。
# ライセンス
このプロジェクトは、[GNU Affero General Public License (AGPL) version 3](https://github.com/bunkerity/bunkerweb/raw/v1.6.15/LICENSE.md) の条件の下でライセンスされています。
# 貢献
プラグインに貢献したい場合は、[貢献ガイドライン](https://github.com/bunkerity/bunkerweb/blob/master/.github/CONTRIBUTING.md)を読んで始めてください。
# セキュリティポリシー
私たちはセキュリティバグを深刻な問題として受け止め、責任ある開示を奨励しています。詳細については、[セキュリティポリシー](https://github.com/bunkerity/bunkerweb/blob/master/.github/SECURITY.md)をご覧ください。
<!-- Star History chart hidden: GitHub restricted the stargazers API, so the chart renders an error
notice instead of data. Uncomment once upstream serves real charts again.
# Star History
<a href="https://star-history.com/#bunkerity/bunkerweb&Date">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://api.star-history.com/svg?repos=bunkerity/bunkerweb&type=Date&theme=dark" />
<source media="(prefers-color-scheme: light)" srcset="https://api.star-history.com/svg?repos=bunkerity/bunkerweb&type=Date" />
Star History Chart
</picture>
</a>
-->