Built for Kubernetes
Define WAF rules using Kubernetes-native CRDs. No more managing complex config files.
Native CRDs
Manage SecRules, SecActions and CRS policies directly in Kubernetes using
SecRule and
SecAction resources.
OWASP CRS Ready
Full support for the OWASP Core Rule Set. Import, customize and manage CRS rules as Kubernetes resources.
ModSecurity Powered
Powered by ModSecurity / Coraza. Battle-tested WAF engine with full SecLang compatibility.
Envoy Gateway
Native integration as Envoy Gateway WAF policies using Kubernetes Gateway API. Apply rules at the gateway level.
Sidecar WAF
Deploy as a sidecar container next to your application pods. Fine-grained per-workload protection using Coraza or ModSecurity.
Get notified when we launch
Join the mailing list for updates on the stable release (expected Q2 2026) and other important announcements.
Thank you! You'll be the first to know about the stable release.
kubeWAF would not be possible without these outstanding open source projects