SWAG (Secure Web Application Gateway)
Nginx webserver and reverse proxy with PHP support, built-in Certbot (Let's Encrypt) client and fail2ban integration.
Maintained, but at a slower pace than the leaders in its category.
Commit activity more than 34% of tracked projects; popularity more than 61%. How this is calculated.
Commits, last 11 months
| Stars | 3.7k |
|---|---|
| Latest release | 5.8.0-ls487 · 26 Sept 2026 |
| Repo updated | 26 Sept 2026 |
| Licence | GPL-3.0 |
| Built with | Docker |
Is SWAG (Secure Web Application Gateway) actively maintained?
SWAG (Secure Web Application Gateway) is under active development: 119 commits landed over the last 11 months, averaging roughly 14 commits a month in the most recent quarter.
Activity is accelerating: the last quarter carried 91% more commits than the one before it.
The most recent tagged release, 5.8.0-ls487, shipped within the last month — a current, installable version exists today.
SWAG (Secure Web Application Gateway) ranks #12 of 19 tracked web servers projects. Several better-maintained options exist in the same category — they are listed below.
What SWAG (Secure Web Application Gateway) actually does
SWAG functions as an Nginx-based web server and reverse proxy, packaging PHP execution, automated Let's Encrypt certificate generation via Certbot, and fail2ban protection into a single containerised application. It is designed to route incoming web traffic while handling encryption and basic intrusion prevention out of the box. The project operates under the GPL-3.0 licence and maintains an active release cycle.
Best fit: It suits self-hosters who want a pre-configured Nginx proxy stack with automated TLS certificate management without manually wiring Certbot and fail2ban together.
Worth knowing: Configuration relies heavily on text-based Nginx files and container environment variables, which can introduce friction for administrators preferring a graphical management interface.
Deployment notes
You will typically need to mount persistent volumes for your configuration files, log outputs, and web root directories, while ensuring ports 80 and 43 for HTTP challenges and traffic are correctly forwarded.
Links
Alternatives to SWAG (Secure Web Application Gateway)
Projects in the same categories, ordered by health score.
Identity-aware tunneled reverse proxy with dashboard UI, access control, and WireGuard-based tunnels (alternative to Cloudflare Tunnel, Tailscale).
HTTP reverse proxy and load balancer that makes deploying microservices easy.
Next-gen Web Application Firewall (WAF) that will protect your web services.
Lightweight, simple, and performant reverse proxy with WebUI, Docker integration, automatic shutdown/startup for container based on traffic.
Docker container for managing Nginx proxy hosts with a simple, powerful interface.
Fast, memory-safe web server written in Rust.