自托管模式
Team owns deployment, upgrades, logs, tuning, and bypass path
WAFWiki 原创实验
用流程图对比自托管 WAF 与托管云/边缘 WAF 在流量路径、运维责任、日志和回滚方面的差异。

证据原则
WAFWiki 会区分已验证的动手实测、冒烟实测、架构图和方法论说明。任何本地实验都只证明记录环境中的有限路径,不代表完整生产就绪。
环境
Team owns deployment, upgrades, logs, tuning, and bypass path
Provider operates the edge platform while the team owns policy and routing choices
Use the same workload, observation window, and false-positive checklist
命令
Replay identical clean workflows through both candidate WAF paths when architecture allows it.对比状态码、延迟、规则事件、请求字段和回滚步骤。
For each candidate, list who owns DNS, TLS, policy changes, upgrades, support escalation, logs, and bypass.风险更低的方案通常是团队能稳定运营并有信心回滚的方案。
观察结果
自托管优势
Good when origin-side control and data locality matter.
托管优势
Good when global edge, DDoS, CDN, bot controls, and support matter together.
优先用流量路径和运营责任作为一阶判断标准。
没有请求量、规则范围、日志和支持需求时,不要直接比较价格。
公平对比应使用同一组代表性业务流程。证据上下文
公开页面展示可安全公开的环境与结果摘要;原始本地日志保留在项目文档中,便于后续复核。
限制
相关研究