Security for the Linux servers you run yourself.
makit finds what is wrong on your server and in its containers, blocks attacks before they reach your app, handles bots and AI crawlers the way you decide, and sets up new servers safely — one open-source command for Ubuntu and Debian.
curl -fsSL https://makit.sh/install.sh | shAs root. Installs the latest release from GitHub, checked against its SHA-256 sums. Read the script first if you like.
makit scanread-only check, asks firstmakit shield on --observesee what it would blockmakit init --dry-runset up a new serverWhat makit does
One CLI for the whole server. The threat knowledge — rules, scoring, bot catalog, vulnerabilities —
is open data in the repository, updated with makit rules update and yours to override.
Check
Read-only check of the host and every Docker container: malware and miners, suspicious processes and connections, persistence, vulnerable npm packages, and the basics — SSH, firewall, Docker ports, updates, kernel, secrets. Every finding links to a guide.
Guides →Protect
A gate for your web traffic: its own IP set (millions of entries, no ipset), allowlist, real client IPs behind Cloudflare, rules and request scoring (probes, XSS, SQL injection), automatic bans. Caddy or nginx asks it, or it stands in front. One server, many domains, each with its own policy.
Shield →Bots & AI agents
Search engines, AI crawlers and assistants, SEO tools, link previews, scripts. Real Googlebot is verified, fake ones are caught; you choose per category or per bot: allow, log, block, ban or rate-limit.
Bots →Alert
Every five minutes, a readable report of what was blocked and why — to Telegram, Slack, Google Chat, Discord, Teams, ntfy, a webhook or email. Scheduled scans report the same way.
Notifications →Set up & harden
A fresh server in one command: upgrades, swap, Docker, a firewall that also covers Docker ports, automatic
updates, kernel and SSH hardening, fail2ban, AppArmor, auditd. Idempotent, with --dry-run.
Watch
A terminal dashboard with mouse support: CPU, memory, processes, containers, services, logs, the shield's switches and lists, and what is still missing on this server.
makit top →Measured, not promised
The shield sits in front of every request, so its cost is benchmarked in the repository — run
benchmark/run.sh on your own machine (Docker only) and compare.
How it is built
- Read-only checks.
makit scanasks for consent and never changes, deletes or uploads anything. - Every change previewable.
--dry-runon every command; running twice is harmless. - No lock-outs. SSH passwords stay on until a key works; your SSH address and Cloudflare can't be banned by mistake.
- Neutral. The bot catalog favours no one; every policy is yours.
- Open data. Rules, scoring sets and the bot catalog are files in the repository you can read and override.
- MIT licensed. Use it anywhere, for anything.