A modern, security-focused reverse proxy manager built on top of Nginx β with a clean web UI, advanced TLS management, and built-in protection features.
Caution
Migration from NPMplus required.
- Update your
compose.yamlto useghcr.io/shedowe19/shieldpm:develop - Data now lives at
/data/shieldpm(auto-migrated from/data/npmpluson first start) - Switched from Alpine to Debian Trixie β use Debian package names (e.g.
php8.2-curlinstead ofphp82-curl) - Downgrading is not possible β back up your data before upgrading
# 1. Download config
curl -o compose.yaml https://raw.githubusercontent.com/shedowe19/ShieldPM/refs/heads/develop/compose.yaml
# 2. Set your timezone and ACME email in compose.yaml, then start
docker compose up -dOpen the admin UI at https://<your-ip>:81 (self-signed certificate β accept the browser warning on first visit).
First login: There are no default credentials β the Setup Wizard creates your admin account on first visit. Automated deployments can set INITIAL_ADMIN_EMAIL and INITIAL_ADMIN_PASSWORD instead.
GeoIP Country, City, and ASN databases are prepared from the latest GeoLite.mmdb release before services start, then checked again on every start. No MaxMind credentials are required. Set GEOIP_AUTO_UPDATE=false for offline or custom databases; enable NGINX_LOAD_GEOIP2_MODULE=true to use country and ASN lookups. See GeoIP setup and startup failures.
- Reverse Proxy β Manage Nginx hosts, redirects, and streams from a clean UI
- SSL/TLS β Automatic Let's Encrypt certificates with HTTP/2 and HTTP/3 (QUIC) support
- WAF β ModSecurity with OWASP CoreRuleSet + OpenAppSec integration
- CrowdSec IPS β Community-powered intrusion prevention
- IP Firewall β Per-host IPv4/IPv6/CIDR lists, TXT/HTTPS imports, optional ASN and country rules, and a page explaining blocked requests
- Cloudflare Tunnels β Create and manage Zero Trust tunnels directly from the UI
- PHP-FPM β Optional PHP 8.2 / 8.3 / 8.4 integration
- Analytics β Built-in GoAccess dashboard on port
:91 - Auth Requests β SSO support via Authentik and similar providers
- Multi-DB β SQLite (default), MySQL/MariaDB, or PostgreSQL
- i18n β UI available in English, German, Spanish, Italian, and more
Full setup guides, configuration options, and advanced usage are in the Wiki.
Die interne Entwicklerdokumentation fΓΌr Entwickler und AI-Agenten befindet sich unter:
# Required toolchain: Node.js 26+ and Yarn Classic 1.22.22
npm install --global --allow-scripts=yarn yarn@1.22.22
# Frontend
cd frontend && yarn install --frozen-lockfile && yarn dev
# Backend
cd ../backend && yarn install --frozen-lockfile && yarn dev
# Verification
cd ../backend && yarn test --run
cd ../frontend && yarn test --run && yarn buildSpecial thanks to @ZoeyVid for the foundational work on NPMplus, and to all contributors who help make ShieldPM better.
Questions or ideas? Head over to GitHub Discussions β we'd love to hear from you.
Maintained with β€οΈ by the ShieldPM Contributors.