Self-hosted model
Team owns deployment, upgrades, logs, tuning, and bypass path
Original WAFWiki lab
A visual comparison of self-hosted WAF ownership versus managed cloud or edge WAF ownership, focused on traffic path, operations, logging, and rollback.

Evidence policy
WAFWiki separates verified smoke-test results from architecture diagrams and methodology notes. A smoke test proves one narrow local path; it does not claim full production readiness.
Environment
Team owns deployment, upgrades, logs, tuning, and bypass path
Provider operates the edge platform while the team owns policy and routing choices
Use the same workload, observation window, and false-positive checklist
Commands
Replay identical clean workflows through both candidate WAF paths when architecture allows it.Compare status code, latency, rule event, request field, and rollback steps.
For each candidate, list who owns DNS, TLS, policy changes, upgrades, support escalation, logs, and bypass.The lower-risk option is often the one the team can operate and roll back confidently.
Observed result
Self-hosted strength
Good when origin-side control and data locality matter.
Managed strength
Good when global edge, DDoS, CDN, bot controls, and support matter together.
Use traffic path and operations ownership as first-order criteria.
Do not compare pricing without request volume, rule scope, logs, and support needs.
A fair comparison uses the same representative business workflows.Evidence context
The public page shows safe excerpts from the recorded environment and results. Raw local logs remain in the project documentation for auditability.
Limitations
Related research