Skip to content

Examples & Cookbook Overview ​

Browse ready-to-run configurations and production blueprints for RouteWarden across different deployment targets.


Scenario Index ​

ScenarioDescriptionTarget
1. Basic Sensitive FilesShield .env, .git, backups, and configs with custom JSON errors.Traefik, Caddy & NGINX
2. Global EntryPoint ShieldProtect all microservices and routes automatically at the proxy gateway.Traefik, Caddy & NGINX
3. Service-Level Docker ComposeTailor rules, custom regexes, and safe allowlists per service.Traefik, Caddy & NGINX
4. IP / Subnet WhitelistingAllow internal corporate VPNs, office IPs, and developer subnets.Traefik, Caddy & NGINX
5. Captcha Verification ChallengeChallenge clients via Cloudflare Turnstile or hCaptcha on sensitive routes.Traefik, Caddy & NGINX
6. Kubernetes IngressRouteProduction Ingress and Middleware setups for Traefik CRDs, Caddy & NGINX Ingress.Kubernetes (Traefik, Caddy & NGINX)
7. CrowdSec Integration & Security LoggingConnect RouteWarden to CrowdSec for instant 1-strike attacker auto-bans.Traefik, Caddy & NGINX + CrowdSec

Production Case Studies ​

Case StudyFocus & Threat ModelProtection Pattern
1. Immich Dual-Router ShieldPublic photo/video sharing without exposing login/admin APIs.Dual Traefik Routers + 404 Masking
2. Zero-Trust WebhooksSecure Stripe/GitHub webhook ingress from unauthorized HTTP injection.Provider CIDR Whitelisting + Silent Drop
3. Observability & Metrics CloakingPrevent public harvesting of Prometheus /metrics and /actuator.VPC / Internal Scraper IP Exemption
4. CMS & WordPress Brute-Force ShieldEliminate credential-stuffing on wp-login.php, xmlrpc.php, and /admin.Cloudflare Turnstile / hCaptcha Challenge
5. Password Vaults (Vaultwarden)Public mobile password sync while restricting /admin to Tailscale/WireGuard.VPN Subnet Filter + 404 Error Cloaking
6. Honeypots & Staging CloakingNeutralize scanning bots and hide pull-request preview clusters from crawlers.TCP RST (silentDrop) & 307 Deflection

Technical References ​

ReferenceDescriptionTarget
Custom Paths & Regex GuideRegex patterns, wildcard rules, and sensitive route catalog.Traefik, Caddy & NGINX
Response Modes ReferenceAll 13 defense action modes, headers, and payload behaviors.Traefik, Caddy & NGINX
Anti-Evasion Security EngineURL normalization, recursive decoders, and directory traversal mitigation.Traefik, Caddy & NGINX

In-Repo Runnable Code ​

All examples are checked directly into the examples/ directory of the RouteWarden GitHub repository. You can clone the repo and run any scenario in seconds:

bash
git clone https://github.com/routewarden/traefik-warden.git
cd routewarden/examples/01-basic-sensitive-files
docker compose up -d

Released under the MIT License.