makit

Security for the servers you run yourself.

  • Checkhost and containers, read-only
  • Protectstop attacks before your app
  • Bots & AIallow, block or rate-limit — your call
  • AlertTelegram, Slack, email and more
  • Set upa hardened server in one command
  • Watcha live terminal dashboard

Install · Ubuntu & Debian, as rootread the script

#curl -fsSL https://makit.sh/install.sh | sh

What makit does

One CLI for the whole server. The threat knowledge — rules, scoring, bot catalog, vulnerabilities — is open data in the repository, updated with makit rules update and yours to override.

makit scan

Check

Read-only check of the host and every Docker container: malware and miners, suspicious processes and connections, persistence, vulnerable npm packages, and the basics — SSH, firewall, Docker ports, updates, kernel, secrets. Every finding links to a guide.

Guides →
makit shield

Protect

A gate for your web traffic: its own IP set (millions of entries, no ipset), allowlist, real client IPs behind Cloudflare, rules and request scoring (probes, XSS, SQL injection), automatic bans. Caddy or nginx asks it, or it stands in front. One server, many domains, each with its own policy.

Shield →
makit shield bots

Bots & AI agents

Search engines, AI crawlers and assistants, SEO tools, link previews, scripts. Real Googlebot is verified, fake ones are caught; you choose per category or per bot: allow, log, block, ban or rate-limit.

Bots →
makit notify

Alert

Every five minutes, a readable report of what was blocked and why — to Telegram, Slack, Google Chat, Discord, Teams, ntfy, a webhook or email. Scheduled scans report the same way.

Notifications →
makit init

Set up & harden

A fresh server in one command: upgrades, swap, Docker, a firewall that also covers Docker ports, automatic updates, kernel and SSH hardening, fail2ban, AppArmor, auditd. Idempotent, with --dry-run.

Commands →
makit top

Watch

A terminal dashboard with mouse support: CPU, memory, processes, containers, services, logs, the shield's switches and lists, and what is still missing on this server.

makit top →

First steps

The installer fetches the latest release from GitHub and checks it against its SHA-256 sums. Then:

#makit scanread-only check, asks first
#makit shield on --observesee what it would block
#makit init --dry-runset up a new server

Measured, not promised

The shield sits in front of every request, so its cost is benchmarked in the repository — run benchmark/run.sh on your own machine (Docker only) and compare.

~9 µsto decide one browser request with every check on
~1 msadded at the median, in front of the app or asked by Caddy
~180 nsper lookup in a 1,000,000-entry IP set
0disk writes in the request path — bans are saved in batches

How it is built

  • Read-only checks. makit scan asks for consent and never changes, deletes or uploads anything.
  • Every change previewable. --dry-run on every command; running twice is harmless.
  • No lock-outs. SSH passwords stay on until a key works; your SSH address and Cloudflare can't be banned by mistake.
  • Neutral. The bot catalog favours no one; every policy is yours.
  • Open data. Rules, scoring sets and the bot catalog are files in the repository you can read and override.
  • MIT licensed. Use it anywhere, for anything.