CLOFIX AGENT v1.0

Lightweight CloFix Nano Agent

Deploy a resilient, server-side validated security agent that filters all ingress traffic. Smart caching and automatic fallback ensure your services stay up, even when the control plane is down.

Server-side validation$5/domainSmart fallbackK8s native99.99% SLA

01 What is the CloFix Nano Agent?

The CloFix Nano Agent is a lightweight, high-performance security proxy that protects any workload regardless of platform. Deploy it as a Kubernetes DaemonSet, sidecar container, standalone Docker container, systemd service, or integrate directly with your existing reverse proxy.

๐ŸŽฏ Core Design Philosophy
โœ… Server-Side Control - All security rules, licenses, and policies are managed centrally on the API server.
โœ… Stateless & Fast - The Nano Agent maintains no local state, caching decisions for sub-millisecond validation.
โœ… Zero-Downtime Fallback - If the API server becomes unreachable, the agent automatically enters fallback mode (bypass/deny/cache_only) to ensure continuous operation.
โœ… Ultra-Lightweight - Consumes only ~50MB RAM and <0.1 CPU core under normal load, perfect for edge deployments.
โœ… Prometheus Native - Exposes all metrics at /metrics endpoint for real-time observability.

Works with Any Infrastructure

โŽˆ
Kubernetes
DaemonSet / Sidecar / Ingress
๐Ÿณ
Docker
Container / Compose / Swarm
๐ŸŸข
Nginx
auth_request module
๐ŸŸก
Apache
mod_auth_request
๐Ÿ”„
Traefik
ForwardAuth middleware
โšก
HAProxy
Lua / http-request
๐Ÿš€
Caddy
forward_auth directive
โ˜๏ธ
AWS ALB / NLB
Lambda / Target Group
๐Ÿ”ท
Istio / Envoy
ext_authz filter
๐Ÿ–ฅ๏ธ
Bare Metal / VM
systemd / binary
โšก
50k+ RPS
Per Node Throughput
๐Ÿ“ฆ
~50MB RAM
Memory Footprint
๐ŸŽฏ
99.99%
Availability SLA
๐Ÿณ
5-Minute
Deployment Time

02 Key Benefits

๐Ÿ›ก๏ธ Complete OWASP Top 10 Protection
Full coverage against A01-A10 vulnerabilities including Injection, Broken Auth, XSS, SSRF, and more. 99.9% attack detection rate.
๐Ÿ”ง Multi-Script Security Engine
Write rules in JSON, Lua, Python, JavaScript, or Go plugins. Auto-reload on changes. 10x faster than traditional WAFs.
โšก Ultra-Low Latency
95% cache hit rate, <5ยตs processing for cached requests. Handles 50k+ RPS on single node.
๐Ÿ” Enterprise License Control
Domain-based licensing, IP whitelisting, monthly quota, agent limits, and feature-based access control.
๐ŸŒ Multi-Platform Support
Nginx, Apache, HAProxy, Traefik, Caddy, AWS ALB, K8s Ingress, Cloudflare Workers, and Istio.
๐Ÿณ Kubernetes Native
DaemonSet with hostNetwork, Helm chart, Prometheus metrics, and automatic sidecar injection.

OWASP Top 10 Complete Vulnerability Coverage

A01:2021

Broken Access Control

  • Path-based authorization checks
  • Forceful browsing prevention
  • Directory traversal detection
  • IDOR protection
A02:2021

Cryptographic Failures

  • TLS/SSL enforcement
  • Weak cipher detection
  • Secure header injection (HSTS, CSP)
  • Sensitive data exposure prevention
A03:2021

Injection Flaws

  • SQL/NoSQL Injection prevention
  • Command Injection blocking
  • LDAP Injection protection
  • ORM Injection detection
A04:2021

Insecure Design

  • Rate limiting & brute force prevention
  • Request throttling
  • Business logic flaw detection
  • Input validation rules
A05:2021

Security Misconfiguration

  • Security headers enforcement
  • Directory listing blocking
  • Default path protection
  • Debug mode detection
A06:2021

Vulnerable Components

  • CMS vulnerability blocking
  • Framework-specific attack prevention
  • Plugin vulnerability detection
  • Known exploit pattern matching
A07:2021

Identification & Auth Failures

  • Brute force protection
  • Credential stuffing prevention
  • Session hijacking detection
  • JWT validation
A08:2021

Software & Data Integrity

  • Deserialization attack prevention
  • Object injection detection
  • Parameter tampering protection
  • Request integrity validation
A09:2021

Security Logging Failures

  • Detailed attack logging
  • Audit trail generation
  • Alert webhooks (Slack, email)
  • Prometheus metrics integration
A10:2021

Server-Side Request Forgery

  • Internal IP blocking
  • Metadata endpoint protection
  • URL allowlist/blocklist
  • Port scanning prevention

Supported Platforms & Integrations

๐ŸŸข

Nginx

Native auth_request module. Sub-request authentication with <5ms overhead.

auth_request /clofix-auth;
๐ŸŸก

Apache

mod_auth_request + mod_proxy. Full compatibility with Apache 2.4+.

AuthRequest "/clofix-auth"
โŽˆ

K8s Nginx Ingress

ExternalAuth with DaemonSet. Prometheus metrics. Auto-scaling with HPA.

nginx.ingress.kubernetes.io/auth-url
โ˜๏ธ

AWS ALB

AWS Load Balancer Controller. Target group routing with forward auth.

alb.ingress.kubernetes.io/auth-type: forward
๐Ÿ”„

Traefik

ForwardAuth middleware. Native Kubernetes CRD support.

forwardAuth.address: http://clofix-agent:8080
๐Ÿ”ท

Istio

EnvoyFilter with external auth. Service mesh integration.

CUSTOM action with ext_authz
๐Ÿš€

Caddy

Forward auth directive. Automatic HTTPS support.

forward_auth http://clofix-agent:8080
โšก

HAProxy

Lua-based external authentication. High-performance with <100ยตs overhead.

http-request lua.clofix-validate

Performance Metrics

99.99%
Uptime SLA
50k+
RPS per node
95%
Cache hit rate
50MB
Memory footprint
5min
Setup time

03 Simple, Transparent Pricing

๐Ÿš€ For Production

Starter

$5/month
+ $5 per domain
  • Up to 1 IP
  • 1 domain included
  • 50K requests/month
  • Email support
  • 99.9% SLA
  • Slack notifications
๐Ÿ’š For CloFix Community
OPEN SOURCE SPIRIT

CloFix WAF Community

Free forever
No credit card required - never converts to paid

Core Security

  • Up to 1 nano agents license
  • 3 domain included
  • 50,000 requests / month
  • OWASP Top 10 Security
  • Weekly rule updates

Monitoring

  • prometheus
  • Slack alerts
  • 99.5% SLA uptime guarantee

Integration

  • ๐Ÿ™ GitHub Access included

Support

  • Community forum support
  • Community life time free
  • Documentation access
  • Discord community
  • Training Session

Forever free for personal use, homelabs, learning environments, and non-commercial applications

04 Domain-Based Pricing

How Domain Pricing Works

Each protected domain costs $5/month. You can protect any number of domains based on your plan's included domains + additional domains.

example.com โ†’ $5/monthapi.example.com โ†’ $5/month*.staging.com โ†’ $5/monthdashboard.company.com โ†’ $5/month
๐Ÿ“Š Example Calculation
Professional Plan ($45/month) includes 10 domains.
If you need 20 domains โ†’ $45 + (10 ร— $5) = $95/month
Each additional domain beyond included limits is just $5/month.
No per-request fees โ€“ Flat pricing
No egress charges
No SSL termination fees
Free 24/7 support
No upgrade costs

05 Compliance Ready

PCI DSS 4.0

Complete logging & auditing for payment card industry.

GDPR

Data anonymization and privacy controls.

HIPAA

Audit trails for healthcare data.

SOC2

Access controls and security monitoring.

ISO 27001

Information security management certified.

06 Domain-Based Filtering

๐ŸŒ How Domain Filtering Works
โœ… Allowed Domains (Server-Side) - Configure which domains the agent protects.
โœ… Bypass for Other Domains - Requests to non-configured domains pass through without validation.
โœ… Central Management - All domain configurations are stored on the API server.
โœ… Per-Domain Pricing - $5 per domain per month.
CloFix Nano Agent License Example:
{
 "license_key": "CLOFIX-XXXX", 
 "plan": "enterprise",
 "organization_name": "CloFix-Infotech",
 "email": "support@clofix.com",
 "allowed_domains": ["example.com", "api.example.com"], 
 "bypass_others": true
}

07 High Availability

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚              Normal Operation (Server UP)               โ”‚
โ”‚  Request โ†’ Agent โ†’ API Server โ†’ Validation โ†’ Allow/Block โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                         โฌ‡
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚            Server DOWN (Automatic Fallback)              โ”‚
โ”‚  Request โ†’ Agent โ†’ Cache โ†’ Bypass/Deny โ†’ Service Continuesโ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
๐Ÿ”„ Fallback Modes
Bypass: Allow all when server down (High availability)
Cache Only: Use cached decisions
Deny: Block when server down (Maximum security)

08 Scalability

                    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                    โ”‚   Load      โ”‚
                    โ”‚  Balancer   โ”‚
                    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                           โ”‚
           โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
           โ”‚               โ”‚               โ”‚
      โ”Œโ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”     โ”Œโ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”    โ”Œโ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”
      โ”‚ Agent 1 โ”‚     โ”‚ Agent 2  โ”‚    โ”‚ Agent N  โ”‚
      โ””โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”˜     โ””โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”˜    โ””โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”˜
           โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
                            โ”‚
                    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
                    โ”‚   API Server  โ”‚
                    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

09 Protected Against

SQL Injection (Union, Time-based, Boolean blind)
XSS (Reflected, Stored, DOM-based)
Path Traversal & LFI/RFI
Command Injection
SSRF & CSRF
Bot attacks & Scrapers
DDoS & Brute force
API abuse & GraphQL attacks
Credential stuffing
Log4Shell & Zero-day exploits
Session hijacking & Fixation
Email spoofing & Phishing
Malicious file uploads
XXE & XML attacks
Deserialization attacks
Cloud metadata access (AWS/GCP/Azure)
Rate limiting bypass attempts
IP spoofing & rotation attacks
And more...

10 Core Benefits Summary

CategoryBenefitImpact
Security99.97% threat detectionBlocks SQLi, XSS, bot attacks
Performance<2ms latencyNo noticeable slowdown
Availability99.99% SLASmart fallback when server down
Cost70-80% reductionLower than traditional WAF
Pricing$5/domainPay only for what you protect

11 How to Integrate

bash
# Deploy agent as DaemonSet
kubectl apply -f https://clofix.com/k8s/clofix-agent-daemonset.yaml

# Configure ingress with auth-url
kubectl annotate ingress my-app \
  nginx.ingress.kubernetes.io/auth-url="http://clofix-agent:8080/validate"

11.5 Grafana Integration

Achieve complete observability into your CloFix Nano Agent deployment. The pre-built Grafana dashboard delivers real-time visualization of all agent metrics including request throughput, latency distribution, cache hit ratios, security violation patterns, DDoS protection events, license consumption, and API server connectivity status.

Grafana Dashboard Overview
Security Metrics Dashboard
Grafana Alerts Configuration
Grafana Alerts Configuration
Grafana Alerts Configuration
Grafana Alerts Configuration

Available Metrics Click any card to view metrics

๐Ÿ“Š Request Metrics
  • Total requests, latency, RPS, active requests
๐Ÿ›ก๏ธ Security Metrics
  • Decisions, violations, attacks by IP/country, DDoS blocks
โš™๏ธ System Health
  • Uptime, memory, CPU, goroutines, availability
๐Ÿ’พ Cache Metrics
  • Hits/misses, size, TTL, evictions, false positive rate
๐Ÿ”‘ License Metrics
  • License validity, expiry days, quota usage
๐Ÿ“ˆ Upstream & API
  • Backend requests, API calls, network latency
๐Ÿ›‘ DDoS Protection
  • Rate limit hits, active blocks, concurrent requests
๐Ÿ’ผ Business Metrics
  • Tenant requests, feature usage, alerts
Download Prometheus Dashboard (JSON)
Quick Setup - Configure Prometheus to Scrape CloFix Nano Agent

3.1 Add CloFix Agent as a Prometheus Scrape Target

1
Open the config file
nano ~/cloudguardian/config/prometheus.yml
2
Append scrape job
Add the clofix_agent job block shown below inside scrape_configs
3
Save and exit
Ctrl+O โ†’ Enter โ†’ Ctrl+X
4
Reload Prometheus
curl -X POST http://localhost:9090/-/reload
5
Verify target is UP
Open http://localhost:9090/targets in your browser and confirm clofix_agent status is UP
prometheus.yml - Append inside scrape_configs
 - job_name: clofix_agent
    static_configs:
      - targets: ["clofix-agent-ip:9090"]
    metrics_path: /metrics
Import Grafana Dashboard
  • Download the dashboard JSON file using the button below
  • Open Grafana (http://localhost:3000) โ†’ Dashboards โ†’ Import
  • Upload the JSON file or paste its contents
  • Select your Prometheus data source and click Import
Verification Checklist
โœ… Agent metrics endpoint accessible: curl http://clofix-agent-ip:9090/metrics | head -20
โœ… Prometheus target UP: http://localhost:9090/targets
โœ… Metrics visible in Grafana: Explore โ†’ Select clofix_agent_requests_total

12 Where to Integrate

Select a service from the left panel to see detailed setup steps and configuration snippets.

Nginx

auth_request module

Apache

mod_auth_request

K8s Nginx Ingress

auth-url annotation

AWS ALB

Lambda / Target group

Traefik

ForwardAuth middleware

Istio

EnvoyFilter ext_authz

Caddy

forward_auth directive

HAProxy

http-request / lua

Nginx Integration

nginx.conf snippet
upstream clofix_agent { server 127.0.0.1:8080; }\nserver {\n    location = /clofix-auth { internal; proxy_pass http://clofix_agent/validate; }\n    location / { auth_request /clofix-auth; proxy_pass http://backend; }\n}
Make sure CloFix Nano Agent is running on port 8080 with valid license.

13 Features

FeatureDescription
Server-side validationAgent forwards request to central API for decision
Smart caching90% cache hit rate, configurable TTL
Domain filteringOnly configured domains are validated
Per-domain pricing$5 per domain โ€“ pay only for what you protect
Fallback modesbypass / cache_only / deny when server down
Prometheus metricsRequest counts, latency, cache hit ratio

14 Deployment

bash
# DaemonSet (K8s)
kubectl apply -f https://clofix.com/k8s/agent-daemonset.yaml

# Docker
docker run -d --name clofix-agent -p 8080:8080 clofix/agent:latest

# Binary
./clofix-agent --license=YOUR_KEY --api=http://api.clofix.com:8081

15 FAQ

โ“ How does domain pricing work?
Each domain you protect costs $5/month. Your plan includes a certain number of domains.
โ“ What if I have 100 domains?
Enterprise plan offers unlimited domains with volume discounts.
โ“ Does the agent store security rules?
No. Only caches decisions. Rules are on the API server.
โ“ What if API server is down?
Enters fallback mode (bypass/cache_only/deny). No downtime.
โ“ Is there a free trial?
Yes! Contact us for a 14-day free trial with 5 domains included.