7,363 open-source and SaaS tools, with GitHub stats refreshed every day.

10 alternatives ranked by real activity

Open-source Cloudflare alternatives

A curated, ranked list of the 10 best open-source alternatives to Cloudflare.

The best open-source alternative to Cloudflare is NGINX. If that doesn't suit you, other good options are Pangolin, SafeLine, CrowdSec and BunkerWeb.

Cloudflare alternatives are mainly networking & VPN tools, but some are also security tools. 10 of them shipped code in the last 30 days, 10 can be self-hosted, and 4 use a permissive licence.

Last updated October 2, 2026 · ranked by GitHub stars, growth and recent commits

NGINX

NGINX is a web server, reverse proxy, load balancer, API gateway and content cache, free under a BSD-style license.

GitHub stars
32k
Last commit
2 days ago
Latest release
release-1.31.6
Licence
BSD-2-Clause
Self-hosted
Yes
nginx.orgNGINX homepage screenshot

NGINX, pronounced engine x, is a web server that also serves as a reverse proxy, load balancer, API gateway and content cache. The official open source repository is written in C and distributed under a simplified two-clause BSD license. Enterprise distributions, commercial support and training are sold separately by F5, Inc.

NGINX is installed software with binary packages for the major operating systems and Linux distributions, in stable and mainline versions, plus Windows executables and dynamic modules. Typical tasks covered by the project's introduction include installing SSL certificates and enabling TLS, load balancing, rate limiting and content caching. Topics on the repository list TCP, UDP and mail proxying, HTTP/2, HTTP/3 and QUIC. You can also build from source, and the full documentation includes a beginners guide, development guide and directive reference.

Key features

  • Web server and reverse proxy
  • Load balancing across upstream servers
  • TLS termination, HTTP/2 and HTTP/3
  • Rate limiting and content caching
  • TCP, UDP and mail proxying
  • Stable and mainline release channels

Pricing: Free and open source under a two-clause BSD license; enterprise distributions and support are sold by F5, Inc.

Read more about NGINXWebsite GitHub

Pangolin

An open-source SASE platform on WireGuard combining zero-trust VPN and proxy access, privileged access control and an AI gateway that understands identity.

GitHub stars
23k
Last commit
yesterday
Latest release
1.24.0
Self-hosted
Yes
Hosted version
Available
pangolin.netPangolin homepage screenshot

Pangolin is an open-source secure access service edge platform built on WireGuard. It aims to connect and protect users wherever they are by combining networking and security in one system: a zero-trust VPN, a zero-trust reverse proxy, privileged access control and a gateway for AI workloads that is aware of user identity, with one identity and policy model underneath.

The project compares its idea to commercial platforms such as Cloudflare One, Zscaler and Prisma, but argues that it is open, self-hostable and light enough to be easy to deploy. Legacy SASE products, it says, are heavy, closed and cloud-locked. Topics include reverse proxy, single sign-on, OIDC, SSH, tunneling, NAT traversal and remote access. Because the source is open to inspection, you can verify how traffic and access decisions are handled.

You can use Pangolin Cloud at app.pangolin.net or run it yourself. The repository's license is listed as 'Other' on GitHub, because it mixes open-source and enterprise components, so check the terms. It suits homelab users, small companies and IT teams that want zero-trust remote access without a large vendor contract.

Key features

  • Zero-trust VPN built on WireGuard
  • Zero-trust reverse proxy
  • Privileged access management
  • Identity-aware AI gateway
  • Single identity and policy model
  • Cloud or self-hosted deployment

Pricing: Basic is free for up to 5 users. Team costs $4 and Business $9 per user per month with a 10-day free trial; Enterprise is custom. Pangolin can run in the cloud or self-hosted.

SafeLine

Self-hosted web application firewall and reverse proxy that filters HTTP traffic to block attacks such as SQL injection, XSS, and bot abuse.

GitHub stars
23k
Last commit
5 days ago
Latest release
v9.4.2
Licence
GPL-3.0
Self-hosted
Yes
ly.safepoint.cloudSafeLine homepage screenshot

SafeLine is a self-hosted web application firewall (WAF) from Chaitin, released under the GPL-3.0 license. It sits in front of a web application as a reverse proxy, so visitors' requests pass through it first. It filters, monitors, and blocks malicious HTTP and HTTPS traffic before that traffic reaches the origin server, and it is also meant to stop unauthorized data from leaving the application.

The firewall targets common web attack classes, including SQL injection, cross-site scripting, command and code injection, server-side request forgery, path traversal, XXE, and remote code execution, as well as brute-force attempts, HTTP floods, and abusive bots. Beyond rule-based filtering, its documented core capabilities include IP-based rate limiting, a web access control list, bot defense, and encryption of the HTML and JavaScript code served to clients.

Security and operations teams that run their own websites or APIs can use it to add a protective layer in front of existing applications. The project is written in Go and hosted on GitHub, and the maintainers provide documentation, a live demo, and a Discord community. Because it is self-hosted, traffic inspection stays on infrastructure you control.

Key features

  • Reverse-proxy WAF filtering HTTP and HTTPS traffic
  • Blocks SQL injection, XSS, and RCE attempts
  • Defense against bot abuse and brute force
  • IP-based rate limiting
  • Web access control list rules
  • HTML and JavaScript code encryption
  • Self-hosted deployment on your own infrastructure

Pricing: Personal is free forever for up to 10 apps. Lite costs $10 per month ($100 per year) and Pro $100 per month ($1000 per year); Ultimate is custom. A 7-day trial is offered.

CrowdSec

CrowdSec is an open-source IDS/IPS, WAF and bot detection engine that blocks malicious IPs using a crowdsourced community blocklist.

GitHub stars
15k
Last commit
today
Latest release
v1.8.1
Licence
MIT
Self-hosted
Yes
docs.crowdsec.netCrowdSec homepage screenshot

CrowdSec is an open-source and participative security solution that detects and blocks malicious behavior on servers. Its Security Engine acts as an all-in-one intrusion detection and prevention system and web application firewall, analyzing log sources and HTTP requests and enforcing decisions through separate remediation components. It runs on Linux, Windows, Docker and Kubernetes.

A Community Blocklist of IP addresses identified as malicious is shared among users, so an address that attacks one participant can be blocked for others before it arrives. Detection and remediation are decoupled, which means logs can be parsed on one machine while blocking happens at a firewall, reverse proxy or CDN elsewhere. A web console supports monitoring and automation.

The README compares it with fail2ban, which reads similar logs, and with ModSecurity, Coraza and naxsi, since the AppSec component is a WAF built on Coraza that loads SecLang rules and the OWASP Core Rule Set. It can also answer suspicious requests with a JavaScript proof-of-work challenge to stop headless scrapers. CrowdSec is written in Go and licensed under MIT.

Key features

  • Log and HTTP request analysis for attack detection
  • Crowdsourced community blocklist of malicious IPs
  • WAF component built on Coraza
  • Remediation at firewall, proxy or CDN
  • Bot detection with proof-of-work challenges
  • Linux, Windows, Docker and Kubernetes support

Pricing: The Security Engine is free and open source under the MIT license.

BunkerWeb

Open-source web application firewall built on NGINX that acts as a reverse proxy with a web UI and a plugin system.

GitHub stars
11k
Last commit
today
Latest release
v1.6.15
Licence
AGPL-3.0
Self-hosted
Yes
bunkerweb.ioBunkerWeb homepage screenshot

BunkerWeb is an open-source web application firewall that protects web services and aims to make them secure by default. It is a complete web server based on NGINX that sits in front of your applications as a reverse proxy, filtering traffic before it reaches them.

It can be deployed in Linux, Docker, Swarm and Kubernetes environments and is configurable through a command line or a web user interface. Core security features ship in the box, and additional ones can be added with a plugin system. Related topics in the repository include ModSecurity, anti-bot protection, DNS blocklists and Let's Encrypt certificate handling.

The software is written mainly in Python and released under the AGPL-3.0 license. The project provides documentation, a demo, community templates, examples and a forum. Its goal is for administrators to get a reasonable level of protection with minimal configuration while keeping room to tune individual settings for their own use cases.

Key features

  • NGINX-based reverse proxy and WAF
  • Secure-by-default configuration
  • Web UI for managing settings
  • Plugin system for extra protections
  • Deploys on Linux, Docker, Swarm and Kubernetes
  • Anti-bot and DNS blocklist options

Pricing: A free open-source edition is available. Paid self-hosted plans are 49 euros (Shield) and 149 euros (Fortress) a month with a 30-day trial; managed Cloud starts from 639 euros a month and Sentinel is custom.

Technitium DNS Server

Technitium DNS Server, a self-hosted authoritative and recursive DNS server with ad blocking, encrypted DNS and a web console.

GitHub stars
10k
Last commit
7 days ago
Latest release
v15.5.1
Licence
GPL-3.0
Self-hosted
Yes
technitium.comTechnitium DNS Server homepage screenshot

Technitium DNS Server is an open-source DNS server that can act as both an authoritative and a recursive resolver. People host it themselves for privacy and security, and it works out of the box with little or no configuration. A friendly web console is reachable from any modern browser.

It can block ads and malware at the DNS level for an entire network. By forwarding queries over DNS-over-TLS, DNS-over-HTTPS or DNS-over-QUIC, it limits what an internet provider can see or tamper with. A local DNS server also gives logs and statistics for understanding network activity, serves many queries from cache, and allows network-wide domain blocking. Repository topics also mention DHCP server functions and DNS-over-Tor.

The server is written in C# on .NET and runs on Windows, Linux, macOS and Raspberry Pi, with Docker support. It is released under the GPL-3.0 license, and the project site at technitium.com provides downloads and documentation. It is suited to home networks and organizations that want more control over name resolution.

Key features

  • Authoritative and recursive DNS server
  • Network-wide ad and malware blocking
  • DNS-over-TLS, HTTPS and QUIC forwarders
  • Browser-based web console
  • DNS logs and statistics
  • Windows, Linux, macOS and Raspberry Pi support

Pricing: Free and open source under the GPL-3.0 license.

ModSecurity

Cross-platform web application firewall engine for Apache, IIS and Nginx that inspects HTTP traffic with SecRules-based rule sets.

GitHub stars
9.8k
Last commit
2 days ago
Latest release
v3.0.17
Licence
Apache-2.0
Self-hosted
Yes
modsecurity.orgModSecurity homepage screenshot

ModSecurity is an open-source, cross-platform web application firewall engine. It started as an Apache module and now serves Apache, IIS and Nginx, protecting web applications from a range of attacks while also allowing HTTP traffic monitoring, logging and real-time analysis through an event-based rule language.

This repository contains libmodsecurity, the ModSecurity v3 library. It acts as an interface to connectors that pass web traffic in, loads and interprets rules written in the SecRules format, and applies them to HTTP content from your application. Version 3 is a full rewrite that removes the Apache dependencies, aims for higher performance and a new architecture, and plans native JSON audit logs.

The older ModSecurity v2.x for Apache is still maintained in its own repository. The code is written in C++ and released under the Apache-2.0 license, under the OWASP organization. Rule sets such as the OWASP Core Rule Set are typically used alongside it.

Key features

  • WAF engine for Apache, IIS and Nginx
  • SecRules rule language
  • HTTP traffic monitoring and logging
  • Connector-based architecture in v3
  • Rewrite without Apache dependencies

Pricing: Free and open source under the Apache-2.0 license.

Zrok

zrok is an open-source tool for sharing web services, files and network resources securely over the internet without firewall or port-forwarding changes.

GitHub stars
4.7k
Last commit
3 days ago
Latest release
v2.0.6
Licence
Apache-2.0
Self-hosted
Yes
Hosted version
Available
zrok.ioZrok homepage screenshot

zrok lets you share web services, files and network resources with other people, whether they are across the internet or on a private network. It is built on zero-trust networking, so it works through firewalls and NAT without port forwarding or other network changes, and it behaves like a secure reverse proxy and peer-to-peer sharing tool.

Getting started takes a few steps: install zrok, create an account with the invite command, using the free zrok.io service, and enable sharing on your machine. After that you can publish a local web app, share a folder or expose a private resource to selected users. The project is part of the OpenZiti ecosystem and written in Go.

zrok is licensed under Apache-2.0. You can use the hosted zrok.io service or run your own zrok instance, which suits developers who need to expose a local service temporarily, teams sharing files securely and homelab owners who want remote access without opening ports.

Key features

  • Share web services without port forwarding
  • File sharing over zero-trust networking
  • Works through firewalls and NAT
  • Public and private share modes
  • Free hosted zrok.io service
  • Self-hostable zrok server

Pricing: The hosted service is free with a 5 GB daily allowance and no card required, and Zrok can be self-hosted at no cost. Commercial options with SLAs are quoted by NetFoundry.

Read more about ZrokWebsite GitHub

PowerDNS

The PowerDNS source repository containing the Authoritative Server, the Recursor and dnsdist, a DNS load balancer, for running DNS infrastructure.

GitHub stars
4.5k
Last commit
yesterday
Licence
GPL-2.0
Self-hosted
Yes
powerdns.comPowerDNS homepage screenshot

This repository contains the sources for PowerDNS, a set of DNS server software. It includes the PowerDNS Authoritative Server, the PowerDNS Recursor and dnsdist, a DNS load balancer. All three can be built from the same repository, although they are also released separately as tarball, deb and rpm packages.

The authoritative server depends on Boost, OpenSSL and Lua and needs a compiler with C++17 support, and the project provides pdns-builder, a Docker-based build process for producing the different releases. Docker images are available, with the README mirrored to Docker Hub, and full documentation lives at doc.powerdns.com.

PowerDNS is copyright PowerDNS.COM BV and many contributors and is distributed under the GNU GPLv2, with the NOTICE file describing the exact license and exception. Bugs are reported on the GitHub issue tracker, and the changelog on the documentation site is the place to check for recent updates.

Key features

  • Authoritative DNS server
  • Recursive DNS resolver
  • dnsdist DNS load balancer
  • Releases as tarball, deb and rpm
  • Docker images and Docker-based builder
  • Documentation and changelog online

Pricing: Free and open source under the GPL-2.0 licence.

Octelium

Octelium is a self-hosted zero trust access platform that can act as a VPN, ZTNA system, API and AI gateway, tunnel service or PaaS on Kubernetes.

GitHub stars
4.1k
Last commit
today
Latest release
v0.43.0
Licence
AGPL-3.0
Self-hosted
Yes
octelium.comOctelium homepage screenshot

Octelium is a self-hosted, open-source platform that unifies zero trust secure access under one system. It is flexible enough to act as a zero-config remote access VPN, a Zero Trust Network Access and BeyondCorp-style platform, an alternative to ngrok and Cloudflare Tunnel, an API gateway, an AI and LLM gateway, and an infrastructure for building MCP gateways and AI agent access.

Repository topics list attribute-based access control, policy as code, WireGuard, QUIC, SSO, multi-factor authentication, OpenTelemetry and SSH access. The README includes use cases, a feature overview, a guide to try it in a Codespace, CLI installation and instructions to install your first cluster. It is written in Go and runs on Kubernetes. It is compared to ngrok, Cloudflare Tunnel and Apigee for different roles.

Octelium is licensed under AGPL-3.0 and you operate the cluster yourself. It suits platform and security teams, homelab users and developers who want to replace several access, tunnel and gateway tools with one self-hosted system.

Key features

  • Zero-config remote access VPN
  • ZTNA and BeyondCorp-style access
  • API, AI and MCP gateway capabilities
  • Tunnel service as ngrok alternative
  • Attribute-based policy as code
  • Runs on Kubernetes clusters

Pricing: Free and open source under AGPL-3.0.

Read more about OcteliumWebsite GitHub

Cloudflare alternatives: questions

What is the best open-source alternative to Cloudflare?
NGINX is the top-ranked open-source alternative to Cloudflare on Enlisted: NGINX is a web server, reverse proxy, load balancer, API gateway and content cache, free under a BSD-style license. Other strong options are Pangolin, SafeLine, CrowdSec and BunkerWeb.
Are these Cloudflare alternatives free?
All 10 are open source, so the code is free to use under its licence, and all of them can be self-hosted on your own server or computer. 2 also offer a paid or managed cloud version if you'd rather not host it yourself.
How is this list of Cloudflare alternatives ranked?
By a score built from GitHub stars, star growth over the last 30 days and how recently the code changed. 10 of these projects shipped code in the last 30 days. Data is refreshed daily, and nobody can pay to move up.

People also look for alternatives to…

View all