Detects and blocks abusive traffic at the kernel (XDP/eBPF) level. For self-hosted/sovereign infra operators who can't afford enterprise DDoS mitigation. Run it locally or behind your reverse proxy. No cloud dependency. No subscription. Just Rust.
Linux-native traffic protection with eBPF/XDP.
RamShield watches traffic from your proxy, spots abusive patterns, and can block offending IPs or networks directly at the kernel level.
The basic loop is simple:
observe → detect → decide → block → expire
Run it:
git clone https://github.com/grep999/ramshield.git
cd ramshield
cargo build --release --locked --features full
Start locally:
```bash
cp config.baseline.toml config.toml
./target/release/ramshield \
--config config.toml \
--no-xdpCheck that it is running:
curl http://127.0.0.1:9999/healthz
./target/release/ramshield-cli statusSee the Quickstart for the full setup.
RamShield collects telemetry, keeps a bounded view of recent activity, and looks for traffic that crosses the configured detection rules.
A block can then move through:
detection
↓
decision
↓
WAL
↓
enforcement
↓
XDP
Blocks have TTLs, can be inspected from the CLI, and are removed when they expire.
ramshield-cli status
ramshield-cli stats
ramshield-cli check <ip>
ramshield-cli info <ip>Manual blocks are available too:
ramshield-cli block <ip> --reason manual --ttl 300
ramshield-cli unblock <ip>
ramshield-cli unblock-cidr <cidr>When XDP is enabled, enforcement happens close to the network interface:
packet
↓
NIC
↓
XDP
├── drop
└── pass
RamShield exposes the XDP state so you can see whether the kernel dataplane is actually active.
RamShield uses TOML.
A starting point is included in the repository:
config.baseline.toml
The configuration covers detection, batching, IPC, dashboard, WAL, XDP, forecasting and memory limits.
See Configuration.
Health:
curl http://127.0.0.1:9999/healthzMetrics:
curl http://127.0.0.1:9999/metricsDashboard and API are available from the same local service.
Quickstart · Operations · Configuration · Architecture · Troubleshooting · Development
cargo test --workspace --locked --features full
cargo fmt --all -- --check
cargo clippy --workspace --all-targets --features full -- -D warningsSee Development.
MIT