A collection of configs and bot tracking to help web servers use arcane magic to deflect their bullshit
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-20 12:30:45 -06:00
cli update for caddyfile bypasses 2026-09-20 12:30:45 -06:00
grimoire neatnik log flags 2026-09-16 01:49:06 -06:00
wards update for caddyfile bypasses 2026-09-20 12:30:45 -06:00
.gitignore initial commit 2026-09-15 20:16:00 -06:00
install.sh initial commit 2026-09-15 20:16:00 -06:00
LICENSE initial commit 2026-09-15 20:16:00 -06:00
README.md update for caddyfile bypasses 2026-09-20 12:30:45 -06:00
VERSION update for caddyfile bypasses 2026-09-20 12:30:45 -06:00

barrier

A collection of configs and bot tracking to help web servers use arcane magic to deflect automated bullshit. It's so stupid we need this stuff now

install

I made it easy. Just paste this in terminal and let the magic happen

curl -fsSL https://source.tube/brindly/barrier/raw/branch/main/install.sh | bash -s -- https://source.tube/brindly/barrier

what's it do though?

It clones the repo and installs the CLI tool globally. It won't activate anything unless you tell it to

Everything lives in /opt/barrier so you can go look for yourself. Or inspect the install scrip. Either way works

uninstall

remove global command

barrier uninstall

nuke everything

barrier uninstall --raze

--raze will ask before running. Just in case. It won't edit the web server configs though so make sure you remove those first

useful commands

Pull latest version. It'll back up any .toml edits you made, and attempt to merge them back in

barrier update

Build wards from grimoire. No flag does all of em. It will wipe out any already in there

You can edit the .toml files in grimoire to add exclusions, or disable entire sections, and generate will respect those

barrier generate [--nginx --apache --caddy --cloudflare --bunny]

Add includes for web server. Supports caddy, nginx, and apache atm. You can also use --site arg to tell it a specific domain you want to target. Otherwise it'll do em all

barrier enable <service> [path] [--site x]

Disables the includes. Basically comments them out

barrier disable <service> [path] [--site x]

Removes the includes. Bye bye

barrier remove <service> [path] [--site x]

Check barrier version. Cause why not

barrier -v

Any command accepts --dryrun as an arg to show what'll without doing stuff. If you're lost, try barrier <command> --help to get more info on a command

exclusions

You can totally tell the system if you want to exclude some of the default blocking. Just go in the .toml files, and either enable/disable whole sections, or just add specifics to the exclusion list (its an array)

Regenerate once saved and the new wards will have your tweaks. Just don't add new things to the toml lists because an update will wipe it. better off doing those in your own block partials seperate from barrier

nginx

As part of the nginx ward, there's 2 includes that get added to an nginx config file. The maps go in http {}, rules go in each server {} block you want protected. Below is a simple example:

http {

    # 🛡️ barrier maps
    include /opt/barrier/wards/nginx/maps/*.conf;

    server {

        # 🛡️ barrier rules
        include /opt/barrier/wards/nginx/server.conf;
    }
}

If adding these manually, you'll want to run the nginx config check, then reload nginx for them to take effect.

apache

Apache is easy its just a single line to include everything. Toss it in any <VirtualHost> you want to shield. Or i guess in a main config too maybe? idk I haven't touched apache in a long time i forgot the ins and outs. I just made sure this worked.

<VirtualHost *:443>

    # 🛡️ barrier wards
    Include /opt/barrier/wards/apache/*.conf
</VirtualHost>

Do a config test and then reload apache for it to engage

caddy

Caddy is the new hotness, so obviously adding that is simple. Just add a little line into any site block you want. Needs to go before handle blocks you have IF you want it to cover everything (order of handle operations thing)

example.com {

    # 🛡️ barrier wards
    import /opt/barrier/wards/caddy/*
}

Make sure to validate and reload caddy for it to start working.

barrier bypass

If you've got some stuff that NEEDS to make it through (and exlcudes aren't enough), you can set barrier_bypass to 1 (or true) and the wards will ignore it

id.example.com {

    # 🛡️ barrier wards
    import /opt/barrier/wards/caddy/*

    # pocketID bypass
    @pocketid path /api/oidc/* /.well-known/*
    vars @pocketid barrier_bypass 1
}

Other patterns work too. so header User-Agent *UptimeKuma* or remote_ip 10.0.0.0/8 would also bypass rules for those. Don't put vars line inside a handle it wont work. it needs to be at the site level (like example). Also needs caddy 2.6 or newer because of a weird var placeholder thing

cloudflare

Each ward in wards/cloudflare/ is a cloudflare formatted rule. In your dashboard, go to "Security > Security Rules", create a custom rule, switch to the expression editor, and paste the file contents all up in there. Set the action to "Block" and hit save. You need 1 rule per file. Generator is designed to keep each one under the 4000 character limit of the free tier

Congrats! You blocking real good.

P.S. - Make sure proxy (orange cloud) is on for DNS entries you're trying to block for. Rules don't work without it.

bunny.net

Wards in wards/bunny/ are 1 edge rule each, formatted for the bunny API. Edge rules only allow 5 conditions per rule so I had to be creative with the generator. It also uses lua patterns which was another hiccup. Anyway thats why there's a ton of files for bunny exclusively

These are meant to be CLI only. Doing it by hand is just not feasible (no expression editor)

barrier enable bunny [--zone 123,456]
barrier disable bunny [--zone 123,456]
barrier remove bunny [--zone 123,456]

If you don't add a zone arg, it'll just ask you. It also requires your bunny API key to do anything, which it will politely ask you for, and store in .local/bunny.key for future use

manual install (wards)

Pre-generated files live in wards/. If you want to just grab files and use them on your server, go ahead thats why they exist. There's stuff for cloudflare, nginx, caddy, and apache. Do whatever works for you

DISCLAIMER

While i've used this myself, its still technically an alpha (CLI not the wards themselves). So if something goes wrong or could be improved PLEEAASSEEE just open an issue for a suggestion or a bug. I don't need to cater to everyone but I do want it to work and be somewhat sane