Docs

Tiyi documentation

Run Tiyi between visitors and your application to protect websites and APIs. Start with installation, login, and your first site, then move to production traffic, protection tuning, automation, and daily operations.

Start here

If you've never run Tiyi before, follow Quickstart. Install, sign in, create one site, and watch the WAF block real attacks. Then continue with Practice and advanced use, or connect your application with the Operations guide.

1Quickstart

Install the signed binary, start the systemd service, create your first site, and watch the WAF block real attacks. Five minutes.

2Installation

One-line installation, manual steps, custom ports, offline setup, configuration, and service management.

Upgrade and migration

Check the backup, fresh-state and remote-Agent re-enrollment requirements before upgrading.

How it works

Sites, upstream pools, certificates, WAF policies, agents, telemetry, and the audit chain — what each one is and how they fit together.

3Operations guide

Connect a real application, inspect traffic and logs, investigate blocks, tune policies, configure alerts, and manage nodes.

Practice and advanced use

Keep using the demo site to explore observe/block modes, rule tuning, API protection, automation, and recovery.

Add Tiyi to an existing Nginx site

Rehearse Nginx integration, inspect real WAF blocks, tune a scoped exception and restore the original route, with tested commands and screenshots.

Automatic remediation

Configure security-threshold alerts, global IP blocking and fixed expiry, then verify results and remove blocks.

Troubleshooting

Diagnose startup, login, routing, TLS, WAF, agent, and observation-pipeline problems from the outside in.

CLI reference

Current commands grouped by resource, with safe examples and a reminder to check each command's built-in help.

API reference

The ConnectRPC contract that drives the UI, CLI, and agent stream: authentication, errors, and the current service catalog.

Deployment

Production hardening, remote-Agent continuity and Controller outage boundaries, SIEM egress, observability, and the upgrade path.

Configuration and templates

Complete startup and resource YAML with downloads, apply steps and verification.

Import and export sites

Portable site bundles, conflict handling, certificate choices and rollback.

API and upload protection

API discovery, document import, JSON learning, request validation and file requirements.

Protection responses

Configure block pages, response statuses and API error formats.

Complete protocol and CLI reference

Look up RPCs, fields, permissions and CLI flags.

v3.8.0 release notes

New capabilities, boundaries and backup/migration requirements before upgrading.

AI operator skill

Install the operator skill to complete authorized tasks through supported Tiyi interfaces.

Design philosophy

Three architectural decisions shape every page that follows:

What these docs are not. These pages cover the operator surface — install, run, secure. The installed binary exposes the API contract; implementation details that are not needed for operations stay out of the public docs.

Versions covered

These docs track the current release. Use upgrade and migration before replacing a binary or moving state. Changes to user-facing behavior are tracked in the changelog. If an example disagrees with the installed binary, tiyi <command> --help is authoritative.

Templates and full reference

Startup tiyi.yaml · Minimal site YAML · Four-kind YAML · Site import JSON · OpenAPI YAML · Local demo API · Protection response JSON.

All RPCs · Permissions · All CLI flags.

Upgrading an existing installation to v3.8.0 requires backup, fresh state, and re-enrollment of all remote Agents. Read the v3.8.0 notes and migration procedure before replacing the binary and restarting. History: v3.7.2 · v3.7.1 · v3.7.0.