makit

Security for the Linux servers you run yourself.

makit finds what is wrong on your server and in its containers, blocks attacks before they reach your app, handles bots and AI crawlers the way you decide, and sets up new servers safely — one open-source command for Ubuntu and Debian.

#curl -fsSL https://makit.sh/install.sh | sh

As root. Installs the latest release from GitHub, checked against its SHA-256 sums. Read the script first if you like.

What makit does

One CLI for the whole server. The threat knowledge — rules, scoring, bot catalog, vulnerabilities — is open data in the repository, updated with makit rules update and yours to override.

makit scan

Check

Read-only check of the host and every Docker container: malware and miners, suspicious processes and connections, persistence, vulnerable npm packages, and the basics — SSH, firewall, Docker ports, updates, kernel, secrets. Every finding links to a guide.

Guides →
makit shield

Protect

A gate for your web traffic: its own IP set (millions of entries, no ipset), allowlist, real client IPs behind Cloudflare, rules and request scoring (probes, XSS, SQL injection), automatic bans. Caddy or nginx asks it, or it stands in front. One server, many domains, each with its own policy.

Shield →
makit shield bots

Bots & AI agents

Search engines, AI crawlers and assistants, SEO tools, link previews, scripts. Real Googlebot is verified, fake ones are caught; you choose per category or per bot: allow, log, block, ban or rate-limit.

Bots →
makit notify

Alert

Every five minutes, a readable report of what was blocked and why — to Telegram, Slack, Google Chat, Discord, Teams, ntfy, a webhook or email. Scheduled scans report the same way.

Notifications →
makit init

Set up & harden

A fresh server in one command: upgrades, swap, Docker, a firewall that also covers Docker ports, automatic updates, kernel and SSH hardening, fail2ban, AppArmor, auditd. Idempotent, with --dry-run.

Commands →
makit top

Watch

A terminal dashboard with mouse support: CPU, memory, processes, containers, services, logs, the shield's switches and lists, and what is still missing on this server.

makit top →

Measured, not promised

The shield sits in front of every request, so its cost is benchmarked in the repository — run benchmark/run.sh on your own machine (Docker only) and compare.

~9 µsto decide one browser request with every check on
~1 msadded at the median, in front of the app or asked by Caddy
~180 nsper lookup in a 1,000,000-entry IP set
0disk writes in the request path — bans are saved in batches

How it is built

  • Read-only checks. makit scan asks for consent and never changes, deletes or uploads anything.
  • Every change previewable. --dry-run on every command; running twice is harmless.
  • No lock-outs. SSH passwords stay on until a key works; your SSH address and Cloudflare can't be banned by mistake.
  • Neutral. The bot catalog favours no one; every policy is yours.
  • Open data. Rules, scoring sets and the bot catalog are files in the repository you can read and override.
  • MIT licensed. Use it anywhere, for anything.