Security for the servers you run yourself.
- Checkhost and containers, read-only
- Protectstop attacks before your app
- Bots & AIallow, block or rate-limit — your call
- AlertTelegram, Slack, email and more
- Set upa hardened server in one command
- Watcha live terminal dashboard
Install · Ubuntu & Debian, as rootread the script
curl -fsSL https://makit.sh/install.sh | shWhat makit does
One CLI for the whole server. The threat knowledge — rules, scoring, bot catalog, vulnerabilities —
is open data in the repository, updated with makit rules update and yours to override.
Check
Read-only check of the host and every Docker container: malware and miners, suspicious processes and connections, persistence, vulnerable npm packages, and the basics — SSH, firewall, Docker ports, updates, kernel, secrets. Every finding links to a guide.
Guides →Protect
A gate for your web traffic: its own IP set (millions of entries, no ipset), allowlist, real client IPs behind Cloudflare, rules and request scoring (probes, XSS, SQL injection), automatic bans. Caddy or nginx asks it, or it stands in front. One server, many domains, each with its own policy.
Shield →Bots & AI agents
Search engines, AI crawlers and assistants, SEO tools, link previews, scripts. Real Googlebot is verified, fake ones are caught; you choose per category or per bot: allow, log, block, ban or rate-limit.
Bots →Alert
Every five minutes, a readable report of what was blocked and why — to Telegram, Slack, Google Chat, Discord, Teams, ntfy, a webhook or email. Scheduled scans report the same way.
Notifications →Set up & harden
A fresh server in one command: upgrades, swap, Docker, a firewall that also covers Docker ports, automatic
updates, kernel and SSH hardening, fail2ban, AppArmor, auditd. Idempotent, with --dry-run.
Watch
A terminal dashboard with mouse support: CPU, memory, processes, containers, services, logs, the shield's switches and lists, and what is still missing on this server.
makit top →First steps
The installer fetches the latest release from GitHub and checks it against its SHA-256 sums. Then:
makit scanread-only check, asks firstmakit shield on --observesee what it would blockmakit init --dry-runset up a new serverMeasured, not promised
The shield sits in front of every request, so its cost is benchmarked in the repository — run
benchmark/run.sh on your own machine (Docker only) and compare.
How it is built
- Read-only checks.
makit scanasks for consent and never changes, deletes or uploads anything. - Every change previewable.
--dry-runon every command; running twice is harmless. - No lock-outs. SSH passwords stay on until a key works; your SSH address and Cloudflare can't be banned by mistake.
- Neutral. The bot catalog favours no one; every policy is yours.
- Open data. Rules, scoring sets and the bot catalog are files in the repository you can read and override.
- MIT licensed. Use it anywhere, for anything.
Contact
Bugs and feature requests go to GitHub issues. For anything else, write to us.