Protect your websites and APIs with a WAF, reverse proxy and web UI in one executable. Connect a site, see why requests were blocked and tune protection from the dashboard. No Docker or external database required.
Watch the complete workflow in the real Tiyi admin, or jump straight to any step. This original recording preserves the complete getting-started flow; see the product tour and docs below for the current interface and new capabilities.
Tiyi replaces a four-service compose file with a single Go process — and adds the things ops teams actually want: live config delivery, audit chain, telemetry, and a typed API that drives both the UI and the CLI.
Eight stable work areas organize Overview, application delivery, protection, fleet, events and logs, detection and response, monitoring, and administration. Responsive navigation, permission-aware groups, server-paged lists, and consistent empty/diff/apply states keep complex workflows learnable.
Coraza compiles structured policies into SecLang while literal IP/CIDR lists and MMDB-backed Country Access run in native handlers ahead of the WAF. New sites start on Light: attack scoring and resource guards stay enforcing while common MIME/parser compatibility mismatches remain observable instead of disruptive. Standard keeps strict protocol enforcement, and per-site overrides, visual rules, paranoia levels, thresholds, and exclusions require no ruleset fork.
HTTP-01, DNS-01 with multi-provider support (Cloudflare live; Route53/Aliyun stubs), wildcard certs, and uploaded enterprise certs. Renewal coordinated across all agents.
One host and certificate can fan out by path to upstream pools with request-header transforms, smooth weighted balancing, active health checks, and bounded retries. Export one site or the complete site set, inspect the portable bundle, then import with explicit conflict handling and rollback.
Same proto schema serves the Vben Admin UI, the tiyi CLI, and the agent stream. Every mutation has one path; the CLI and API stay in lockstep by definition.
One writable Controller includes a built-in local data plane. Nodes → Install guides binary download, token issuance, systemd setup, or foreground startup for each remote Agent, which keeps proxying with the last accepted bundle while the Controller is unavailable.
HTTPS sites can require silent browser proof-of-work or private WebAuthn confirmation. Rolling-window limits add temporary site/global bans and independent challenge responses; subscribed provider IP feeds publish atomic last-good snapshots and never become trusted implicitly.
Overview, Enforcement and threshold alerts use security counters collected before sampling. Event Analysis keeps sampled relationship pivots, while Logs → Bot Analytics shows admission outcomes. Coverage gaps stay visible alongside API Inventory, WAF pressure, retained evidence and protected local Prometheus metrics.
Every mutation — including IP-list bindings, rate-limit endpoints, and trust-profile changes — appends a signed audit row. The ledger shows operator and resource names with readable summaries; daily anchors and an in-UI Verify chain button keep tamper-evidence operational. Display timezone follows browser override → app.timezone → browser IANA while storage stays UTC.
Fresh installs retain bounded request headers/body evidence for security events; the in-console preview now starts with an HTTP-style request line. Operators can turn it off or attach it to retained Attack and Access logs. Independent producer-side SIEM queues send native Caddy/Coraza or formatted events over UDP, TCP, or TLS without entering the request path.
An executable node/edge/rule graph replaces scattered XFF parsing. Named proxies consume ordinary manual or subscribed IP lists, each Header selects verified-proxy peeling or fixed-position extraction, and fail-closed analysis produces reviewed drafts without silently trusting a provider feed.
Embedded OWASP CRS 4.25 ruleset, offline archive upload for CRS and exclusion packages, KEK-envelope encryption for secrets at rest, and a persistent ed25519 bundle-signing key the agent pins on first contact.
Rules debounce into a durable pending → firing → resolved lifecycle with explicit outcome, evidence time, observation time, grouping, silences, and per-event channel content. Operators can replay a retained occurrence through the production evaluator without sending notifications.
Admitted samples of blocked or suspicious requests write immutable, partitioned SecurityFact. From Attack Logs, operators draft by intent: block the exact method/path, tune a CRS false positive, or confirm a high-risk CRS-only skip that keeps Tiyi custom and IP controls active. Global IP actions stay separate. Nothing applies without review.
An optional, default-off LLM layer beside the deterministic WAF — never in the request path. Explain a security event or log entry, translate plain-English questions into log queries, and get policy-tuning or custom-rule drafts you approve by hand. Provider-agnostic (OpenAI-compatible, Azure, Ollama, vLLM); every prompt redacted, dual-RBAC gated, and rate-limited.
Argon2id local accounts, OIDC, SAML, LDAP, and RADIUS share one login surface. TOTP enrollment and recovery, password/session controls, custom roles, and generated fail-closed authorization protect every API, UI, and CLI path.
tiyi apply -f site.yaml applies a reviewed manifest and produces an audit receipt for each changed resource. Use --dry-run and tiyi diff to inspect changes first. Same validator, same mutator — by construction.
Discover the APIs your application actually serves. Compare observed traffic with your reviewed catalog, inspect request counts and response codes, and keep catalog membership independent of validation.
Import OpenAPI or Swagger, review address mappings, or learn JSON field names and types from supported requests. Review and export an OpenAPI draft, then choose Off, Observe or Enforce per endpoint. Learning never enables enforcement automatically.
Keep body and upload capacities in the site policy, and define allowed file formats per endpoint and file field. Inspect supported file and container structures, review violations, and confirm application on each serving node. File checks do not perform antivirus scanning.
Enable a security-threshold rule to add eligible source IPs to a global deny list. Set a fixed expiry, inspect action receipts and serving-node results, and remove entries when needed.
Every screenshot below was captured against a running Tiyi instance. Same data plane, same UI, same RPC.
A site's operational overview joins its public hostname, TLS, WAF policy, path routing, upstream health, and exact 24-hour counters into one request path.
Immutable, partitioned security facts turn the attack stream into three investigation perspectives without inventing sessions or putting analytics in the request path.
The event drawer keeps the request identity, Geo/ASN context, CRS matches, actual detection values, and response controls together without obscuring the underlying log stream.
The focused tuning workspace makes each protection layer explicit, then compiles the structured policy into deterministic SecLang on save.
Traffic analysis shows live QPS and exact rankings. API Assets has its own site workspace for discovered endpoints, explicit catalog membership, request definitions and validation.
Enable automatic remediation on a security-threshold rule to add eligible source IPs to a global deny list. Choose a fixed expiry, review the action receipt and verify serving-node results; remove entries when needed.
The same binary runs as Controller or Agent. The built-in local data plane and every remote node share live metrics, config revision, and install guidance from one Nodes surface.
Site, policy, trust-profile, IP-list, and auth changes append signed audit rows. Operators verify the chain in-product instead of trusting an export.
See observed and documented APIs together, with request counts, response codes and validation status. Find interfaces that have not yet joined your reviewed catalog.
For supported JSON requests, Tiyi learns field names and types without retaining field values in the learning model. Review the result, save a version and download an OpenAPI draft.
Import OpenAPI 3.0, 3.1, 3.2 or Swagger 2.0 in JSON or YAML. Review the interfaces and address mappings before applying the document.
Choose off, observe only or enforce for each interface. Enforcement is available for fully supported request definitions; the console shows whether the serving node has applied the change.
Review conforming requests, violations and requests that could not be evaluated. Follow the evidence for the selected interface and time range.
Follow the protection chain to see where a request was stopped, then open enforcement records for the details. Traffic and runtime health stay in the same overview.
Choose allowed file formats per endpoint while site policy owns upload capacity. Avatar uploads and document attachments can have different file requirements.
Tiyi is proprietary software with Apache-2.0 upstreams. The same binary runs Community, Pro, and Enterprise; a signed license raises the remote-node budget. The control plane runs on your hardware.
For homelabs, side projects, and getting to know Tiyi.
One built-in local node. Full product feature set.
For teams running production on a handful of nodes.
Per Tiyi deployment. Annual billing available.
For regulated environments, air-gapped sites, and global edges.
Custom pricing tied to your fleet and SLA.
Need something specific? [email protected] · All plans use the same binary and include the full WAF feature set; the differences are licensed scale, support, and supply-chain services.
Answers about free use, connecting an existing site and everyday operations.
Community includes one built-in local node, the full product feature set, and unlimited sites and policies. No license file is required. Adding remote nodes requires a signed license. Compare editions or start with Community.
Tiyi is proprietary software with a free Community edition. It builds on open-source components including Caddy, Coraza and OWASP CRS. The public repositories provide signed releases, installation tools and documentation, not the Tiyi application source. See the terms of service and the EULA included in the distribution.
Yes. Tiyi acts as a reverse proxy in front of an HTTP backend. First test the route to your existing application. If ports 80, 443 or 8080 are occupied, use custom ports. Before switching real traffic, check domain routing, certificates and how to restore the previous route in the deployment guide.
A Linux amd64 or arm64 host; the default service installation uses sudo and systemd. You can follow the Quickstart with a local demo backend and no DNS changes. CPU, memory and disk needs depend on traffic, rules and retained logs, so test your own workload before production use. Offline installation is also available.
Use the request ID to find its attack log and inspect the matched rule and request evidence, when retained. Prefer a narrow exception for the affected site, path and rule, then verify both normal traffic and attack blocking. See WAF tuning for the workflow.
Start with a complete backup and check the target release's compatibility notes. Compatible releases support signed updates; incompatible state may require rebuilding configuration. Moving to another host also requires the matching version and complete state and configuration. Follow upgrade and migration before changing an existing installation.
Every entry maps back to a commit and a verification command. The full release history lives at /changelog.
Reviewed OpenAPI catalogs, per-endpoint validation, automatic JSON learning and site-owned upload controls. Exact security counters, scoped IP remediation, shared protection responses and bounded console/runtime recovery complete this release.
Upgrade: v3.8.0 requires fresh state; back up, rebuild and re-enroll Agents. Release notes · Upgrade steps.
Configure six terminal scenarios with shared HTML, JSON, text and XML templates. Give visitors a useful message and request ID; keep saved drafts while switching settings groups.
Retry temporary session failures, DNS renewal and node application with explicit results. Bounded diagnostics and health probes keep slow consumers from holding up normal request handling.
Dates are targets, not promises. Items move with verification, not optimism.
Reviewed OpenAPI catalogs, per-endpoint validation, automatic JSON learning and site-owned upload controls. Exact security counters, scoped IP remediation, shared protection responses and bounded console/runtime recovery complete this release.
Upgrade: v3.8.0 requires fresh state; back up, rebuild and re-enroll Agents. Release notes · Upgrade steps.
Install on Linux, connect a test site and verify normal traffic and attack blocking. Start free on one local node.