# Janusec/janusec

JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关，提供安全的接入，包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。

Repository: https://github.com/Janusec/janusec
Canonical: https://ross.abutalabs.com/products/janusec
Homepage: https://janusec.github.io/
Language: Go
License: NOASSERTION
License Family: other
Topics: waf, web-application-firewall, application-gateway, load-balance, gateway, application-security, golang, security, web-application-security, sql-injection, janusec-application-gateway, web-ssh, janusec, port-forwarding, acme, k8s-ingress-controller, cookie-banner, gslb, cookie-compliance
Last push: 2026-07-18T14:39:51+00:00

## Health v2 (maintenance only)
Score: 83/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 93, release rhythm 61, longevity 100
- inputs: {"age_days": 2972, "days_push": 46, "days_rel": 46, "gap_med": 248.5, "n_releases_24m": 3}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1200, forks 268 (observed 2026-08-28T04:03:58.088686+00:00)

## What it is
Janusec Application Gateway is a Go-based application gateway providing secure access for web applications, including reverse proxy, WAF, CC defense, OAuth2/LDAP/CAS authentication, and automatic ACME HTTPS certificates. It also functions as a K8S Ingress Controller and supports TCP/UDP forwarding, GSLB load balancing, and cookie compliance management.

## Use cases
- protect web apps from SQL injection and XSS with a WAF
- block CC attacks and add CAPTCHA challenges
- terminate HTTPS with automatic ACME certificates
- act as a Kubernetes ingress controller
- add OAuth2 authentication in front of internal apps
- load balance traffic across multiple backend nodes
- forward TCP/UDP traffic for non-web services
- show a cookie consent banner for compliance

## When to choose
- you need a self-hosted all-in-one gateway with WAF, auth, and TLS on Linux
- you want a K8S ingress controller with built-in web application firewall
- you need CC attack defense and CAPTCHA without deploying agents

## When to avoid
- you need a production gateway on Windows or macOS
- you prefer a cloud-managed gateway service
- you need a lightweight proxy without WAF features

## Facets
- artifact type: service
- maturity: active
- function: api-gateway, proxy, security, auth, load-testing, middleware, http-server, routing
- domain: security, web-development, backend, networking, self-hosted
- platform: go, self-hosted
- tags: waf, reverse-proxy, application-gateway, k8s-ingress-controller, acme-certificates, cc-defense, gslb, oauth2, cookie-compliance, sql-injection-protection, xss-protection, load-balancing, web-ssh, port-forwarding, devops, linux, web-server, docker

## Member repositories
- Janusec/janusec (main) score 83

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:03:58.088686+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T06:20:44.983475+00:00, confidence not recorded.
  - readme: https://github.com/Janusec/janusec (fetched 2026-08-28T04:03:58.088686+00:00, sha 25d802ce83b1)
  - homepage: https://janusec.github.io/ (fetched 2026-08-29T12:27:56.558683+00:00, sha 1c81101edce1)
- Data as of 2026-08-30T08:39:29.467469+00:00.
