ShieldPM is an advanced fork of Nginx Proxy Manager (NPM), designed to provide a secure, high-performance, and user-friendly way to manage your Nginx reverse proxies.
- HTTP/3 (QUIC): Native support for the latest web protocol.
- Security First: Integrated CrowdSec (IPS) and ModSecurity (WAF) support.
- Advanced TLS: OCSP Stapling, Must-Staple, and support for various ACME providers.
- Database Flexibility: SQLite (default), MySQL, MariaDB, and PostgreSQL support with Auto-Migration.
- Enhanced Management: Access Lists (incl. mTLS), Audit Logs, and Stream/Redirection hosts.
- Installation: Get started with Docker Compose and migration guides.
- Proxmox LXC Installation: Setup guide for Native Containers (Systemd).
- Configuration: Environment variables and database setup.
- User Management: Accounts, roles, and permissions.
- IPv6 Configuration: Setup guide for Docker and IPv6.
- Docker Compose Reference: Full reference file with all options.
- Prerequisites & Best Practices: Backup strategies, security hardening, and performance tips.
- Cookbook & Recipes: Configuration guides for Nextcloud, Home Assistant, Jellyfin, and more.
- Backup & Restore: Dedicated guide for backing up and restoring your instance.
- Glossary: Definitions of common terms.
- Proxy Hosts: Hosts, locations, cache, upstream monitoring, and diagnostics.
- Stream Hosts (TCP/UDP): Forward raw TCP/UDP traffic (Game Servers, Databases, VPN).
- Turbo-Loader (Parallel Downloads): Accelerate large file downloads.
- Redirection & Dead Hosts: Managing 301/302 redirects and 404 blocks.
- Disable Buffering: Optimizing for streaming services (Jellyfin/Plex).
- Maintenance Features: Configuring automatic maintenance pages for downtime.
- Service Icons: Auto-detection and custom icons for your hosts.
- SSL Certificates: Let's Encrypt, Custom Certs, and HSTS best practices.
- Security Overview: Introduction to security features.
- CrowdSec Deep Dive: Setup, Bouncer, and Collections.
- ModSecurity Deep Dive: OWASP CRS, Paranoia Levels, and Tuning.
- OpenAppSec WAF: Optional AI WAF agent and advanced model setup.
- Two-Factor Authentication (2FA): TOTP, YubiKey, Passkey (FIDO2), and Duo Security.
- Access Lists: Basic Auth, IP Ranges, and Authorization.
- OAuth2-Proxy Integration: Setup Single Sign-On using Google, GitHub, Azure, OIDC, etc.
- Anubis Proof-of-Work Gate: Challenge automated clients before they reach a protected host.
- Request Rate Limiting: Protect hosts from abuse and DDoS.
- Internal PKI & ML-KEM: Setup and use the internal Certificate Authority with Post-Quantum security.
- Secure Demo Mode: Architecture and deployment of the public sandbox environment.
- 2026 Audit Report: Full-system security and architecture audit findings.
- Advanced Analytics: Real-time traffic insights and status code breakdown.
- Cloudflare Tunnels: Native support for exposing services via Cloudflare Zero Trust.
- Tor Onion Services: Expose services via Tor Hidden Services for privacy and CGNAT bypass.
- WireGuard Tunnels: Self-hosted VPN tunnel to expose home services behind CGNAT/DS-Lite.
- GitOps Synchronization: Backup, version control, and restore your configuration with Git.
- Dynamic DNS (DDNS): Built-in DDNS client for Cloudflare, DuckDNS, and Custom URLs.
- Docker Auto-Discovery: Automatically expose containers using labels (Traefik-like).
- Git Auto-Deploy: Auto-sync static sites/apps from Git repositories.
- PHP Hosting: Host PHP apps (Nextcloud, WordPress) directly with ShieldPM (No extra container needed).
- Advanced Usage: GoAccess analytics, Dashboard Notes, and custom configs.
- AI Agent (Administrator): Configuring and using the AI Co-Pilot.
- ChatOps (Telegram Bot): Manage ShieldPM via Telegram using the AI Agent.
- Architecture & Internals: Data flow, file structure, and internal CLI tools.
- API Documentation: Developer reference for the REST API.
- Troubleshooting: Common issues and solutions (FAQ).
- Development: How to build and test ShieldPM locally.
- CLI Reference: Documentation for internal scripts and
cscliusage.