Cybersécurité95

Tiyi

Tiyi: website protection in one binary, with AI Copilot and Skills for operations

r/selfhostedu/Otherwise-Step-595726 septembre 2026

Capture du projet

Résumé

Tiyi est un système de protection de site web qui intègre un pare-feu d'applications web, un proxy inverse, une gestion des certificats HTTPS et une analyse de trafic. Il utilise Claude Code pour fournir des guides de tâches pour l'installation et la configuration, ainsi que pour l'analyse des menaces et la génération de règles de sécurité personnalisées.

Pourquoi c’est intéressant

Tiyi est intéressant car il propose une solution complète et intégrée pour la protection des sites web, avec une interface utilisateur simple et une analyse de trafic avancée. L'utilisation de Claude Code pour la génération de règles de sécurité et la résolution des problèmes ajoute une valeur supplémentaire à la solution.

Comment Claude est utilisé

Le projet utilise Claude Code pour fournir des guides de tâches pour l'installation, la configuration et la résolution des problèmes via l'agent tiyi-operator Skill.

Idées dérivées

  1. 01

    Système de protection de site web avancé

    Développer un système de protection de site web intégrant Claude Code pour l'analyse des menaces et la génération de règles de sécurité personnalisées.

  2. 02

    Outil d'automatisation de la sécurité

    Créer un outil d'automatisation pour la configuration et la gestion des règles de sécurité pour les sites web, en utilisant Claude Code pour la génération de règles et la résolution des problèmes.

  3. 03

    Système d'analyse de trafic web

    Concevoir un système d'analyse de trafic web intégrant Claude Code pour l'analyse des données et la détection des menaces, et fournissant des recommandations pour améliorer la sécurité du site.

Afficher le post original
Zero external runtime dependencies · Full features free on a single node · Built-in AI Copilot · Operator Skills One file gets you website protection and its management UI. Tiyi bundles a WAF, reverse proxy, HTTPS, API security, automatic remediation and an AI assistant into one Linux binary. No Docker, external database or separate language runtime is needed. I maintain Tiyi. Local single-node use includes the full feature set, with no limit on sites or policies. Here is what it does and how to get your first site running. From connecting a site to handling attacks • Manage website traffic in one UI: configure sites, path routing, upstreams and HTTPS certificates. • Protect against common attacks: built-in OWASP CRS detects SQL injection, XSS and other attacks. Add custom rules, IP controls and rate limits for your own policies. • Cover your APIs too: discover endpoints, organize an API inventory, import OpenAPI definitions, learn schemas and validate requests. • See what happened: inspect traffic, attack logs, matched rules and request details in the dashboard. • Handle repeat attacks automatically: enable alert-driven IP blocking, set an expiry and check execution results. Let AI help with attack analysis and operations Not sure what an attack log means? Ask AI. The built-in AI Copilot can explain individual records and answer questions such as “What attacks hit my website today?” or “Which IPs attacked most in the last hour?” It can also draft custom rules for you to review and apply. Connect an OpenAI-compatible provider or a local model through Ollama. Want help setting it up and keeping it running? Install the operator Skill. The tiyi-operator Skill (https://github.com/zzmzm/tiyi#ai-agent-skill) gives assistants such as Codex and Claude Code task guides for installation, site onboarding, HTTPS, API protection and troubleshooting. For example: “Connect my website to Tiyi, configure HTTPS and check that protection works.” The assistant works within the access and authorization you provide, with guidance for both configuration and verification. Get started in three steps 1. Install and start it On a fresh Linux host with systemd (amd64 or arm64): bash curl -fsSL https://www.tiyisec.com/install.sh | bash && sudo tiyi install --now This downloads and verifies the binary, starts the service and enables it at boot. The initial admin username and password appear in the terminal. 2. Open the dashboard and add your site Open http://YOUR_SERVER_IP:8080 and sign in as admin with the password from the terminal. Go to Application Delivery → Sites → New. Enter a site name, hostname and upstream address. If your application runs on port 9000 on the same host, use http://127.0.0.1:9000 as the upstream. Keep WAF enabled with the built-in Light policy and save. Point your hostname at Tiyi and configure its certificate when using HTTPS. Existing Nginx users can also put Tiyi between Nginx and their application (https://www.tiyisec.com/docs/existing-site.html). 3. Visit your site and check protection Visit the configured hostname. The dashboard shows traffic, while attack logs show blocked requests, matched rules and request details. Adjust policies in the UI and add alerts with automatic remediation when you need them. Overview and screenshots (https://www.tiyisec.com/) · Installation guide (https://www.tiyisec.com/docs/quickstart.html) AI disclosure: I used AI assistance to prepare this post. The optional AI Copilot and operator Skill are described above; request blocking is handled by the WAF rules.