Biru adalah web server multi-engine berkinerja tinggi. Tulis file PHP, Python, C, Go, atau 48+ runtime lainnya. Taruh di folder webroot Biru mengkompilasi / menginterpretasikannya dan merendernya jadi halaman HTML. Tanpa daemon build, tanpa config ekstra
Jalan di Linux, BSD, Solaris, macOS, dan Android (Termux).
Web server lain butuh compiler, proses build, config panjang, dan butuh wrapper seperti CGI atau penghubung lain. Biru tidak.
Buat file apa saja: index.php, index.py, index.c, index.go, bahkan index.asm.
Letakkan file di webroot. Itu saja. Tidak ada perintah lain, tidak ada service.
Biru deteksi bahasanya, render, lalu tampilkan jadi halaman. Selesai.
Tidak ada modul berbayar, tidak ada plugin terpisah. Semua aktif lewat config JSON.
Biru memakai compiler atau interpreter yang sudah terpasang di server.
PHP 4.3 sampai 9.0 dalam satu server. Tiap situs pilih versinya sendiri.
Biru paham direktif ala Apache. Situs lama sering tinggal di-copy.
RewriteRule: [P] [R] [F,L] [QSA]Jalankan aplikasi sungguhan, bukan cuma script.
Arahkan Biru ke service lain, lalu dia teruskan request.
Perlindungan langsung jalan dengan default yang masuk akal.
Dibuat untuk situs sibuk, bahkan di VPS RAM 512 MB. Terukur: ±14 MB RAM & <1% CPU saat idle (binary ±30 MB).
Ubah config situs, terapkan tanpa henti server.
Bebas jumlah situs dalam satu server, tiap situs terisolasi.
*.domainDua kemampuan yang paling sering dicari, WAF dan worker persistent, sudah bawaan, bukan add-on.
Biru memakai anomaly scoring: setiap request dicocokkan dengan 30 aturan built-in. Skor menumpuk, request dengan skor tinggi diblokir. Severity 5 selalu diblokir.
detect (log saja) → block (403)"sqli": "block", "bots": "block"PHP, Python, Perl, Ruby, Node.js, dan shell dijalankan lewat worker persistent. Proses interpreter tetap hidup, opcache tetap panas, tanpa spawn per request.
"php_mode": "worker", opcache panas.py .pl .rb .sh dan lainnya.js .mjs .cjs statis secara default, aktif runtime lewat "nodejs": trueuser+runtime, recycle otomatisRLIMIT per worker + cgroup cell, satu bocor, tidak merusak hostBiru memakai compiler atau interpreter di mesin kamu. Tidak perlu download atau konfigurasi apapun lagi.
...dan masih banyak lagi. Bahasa baru cukup dengan menginstall compiler-nya di server.
Semua di bawah aktif lewat config JSON, global atau per situs, plus plugin WebAssembly.
*.wasm di-load dari plugins_dir dan dijalankan sandbox di dalam proses. Setiap request bisa pass, respond, deny, atau redirect. Plugin yang error atau lemot dilewati dan di-log, tidak pernah merusak situs.Biru tidak menjalankan interpreter setiap request. Ia memelihara worker yang hidup lama per user dan runtime. Opcache tetap panas, PHP dan script lain jadi lebih cepat.
Atur "php_mode": "worker". Worker di-spawn per user|versi|worker, request dikirim lewat pipe, opcache tetap panas.
Worker memakai SAPI cli → php://input kosong (body tetap diparse jadi $_POST/$_FILES; aplikasi yang baca body mentah seperti WP REST/webhook JSON perlu mode FastCGI). Cookie/session tetap jalan lewat biru_sync_session_cookie() di worker.php.
"php_mode": "fastcgi" (default) memakai SAPI cgi-fcgi → php://input jalan penuh (WP REST, Laravel, Symfony, webhook). Config php_cgi_define menambah argumen -d ke tiap php-cgi; default request_order=GPCS & variables_order=GPCS supaya $_REQUEST + cookie parity dengan mode worker.
Atur "runtime_worker": true. Script .py, .pl, .rb, .sh dijalankan interpreter persistent dari PATH host atau toolchain bawaan.
Mode 1 — skrip: aktifkan "nodejs": true (global/per-situs); .js/.mjs/.cjs dieksekusi per-request ala CGI. Mode 2 — aplikasi: blok "node" (atau biru app nodejs <domain>) menjalankan worker persistent yang mendengarkan PORT/HOST, semua request di-proxy ke sana, restart otomatis saat kode berubah (watcher full-docroot, ala pm2).
Tiap worker di-cap RLIMIT_* (CPU, RAM, disk) lewat wrapper ulimit. Satu worker bocor tidak bisa menghabiskan RAM host.
Worker bisa dipindah ke cgroup cell (v1/v2). LVE CloudLinux dibaca dan diubah jadi rlimit sebagai pengaman tambahan.
File kosong {} saja sudah cukup, Biru jalan dengan default yang masuk akal. Ini contoh asli dari dokumentasi.
# Cara paling mudah (Linux/BSD/Solaris/macOS/Termux)
$ bash <(curl -sL biru.okane.id)
# Install dengan runtime opsional (php, node, python, dll)
$ bash <(curl -sL biru.okane.id) --runtimes
# Dari bundle rilis
$ ./install.sh --no-deps --no-systemd
# Reload vhost tanpa downtime
$ systemctl reload biru # atau: biru reload
blacklist/rate_limit, cukup reload).{
"name": "biru", "version": "1.0.0",
"listen": "0.0.0.0",
"http_port": 80, "https_port": 443, "h3_port": 443,
"hosts_dir": "/home/panel/hosting",
"vhosts_dir": "/home/panel/config/biru/vhosts",
"chroot": "/home/server/apps",
"php_workers": 2,
"php_bin_template": "/usr/local/php/{version}/bin/php-cgi",
"dynamic_cache": { "enabled": true, "ttl": "60s", "max_mb": 64 },
"waf": { "enabled": false, "mode": "detect" },
"geoblock": { "enabled": false },
"rate_limit":{ "enabled": true, "requests": 1000, "window": "1s" },
"blacklist": ["1.2.3.4", "5.6.7.0/24"],
"cell_root": "/sys/fs/cgroup"
}
hosts_dir atau vhosts_dir · aktif setelah systemctl reload biru.{
"active": true,
"domain": "mysite.com",
"aliases": ["www.mysite.com"],
"user": "mysite",
"webroot": "/home/host/mysite/web/mysite.com",
"index": ["index.php", "index.html"],
"php_version": "8.3",
"php_workers": 4,
"php_max_concurrency": 8,
"htaccess": true,
"ssi": true,
"cgi": { "enabled": true, "extensions": [".pl", ".py", ".cgi"] },
"proxy": { "enabled": false, "targets": ["127.0.0.1:3000"] },
"tcp_proxy": { "enabled": false, "targets": ["127.0.0.1:25565"] },
"ssl": { "enabled": true, "auto": true },
"force_https": true,
// Deny-list per situs: IP ini selalu 403
"blacklist": ["203.0.113.11"],
// Batas resource + cell cgroup
"ram_mb": 256,
"cell": "user1"
}
dynamic_cache global untuk semua situs; per-vhost override satu situs. Reset tanpa downtime: biru reset cache atau systemctl reload biru.// 1) Aktifkan cache global (config.json)
{
"static_cache": true, // cache file statis
"dynamic_cache": { // cache respons render
"enabled": true,
"ttl": "60s", "max_ttl": "1h",
"max_mb": 64, "max_file_mb": 4,
"query": "exact",
"skip_cookie": true, "skip_authorization": true,
"cache_header": true,
"statuses": [200, 301, 302]
}
}
// 2) Per-situs (vhost), hanya situs ini
{
"dynamic_cache": { "enabled": true, "ttl": "120s", "max_mb": 128 }
}
// 3) Pilih provider SSL (ACME), "letsencrypt" / "zerossl"
// Global: semua situs pakai ZeroSSL
{ "acme_directory": "zerossl" }
// Per-situs: situs ini override ke ZeroSSL
{ "ssl": { "enabled": true, "auto": true, "directory": "zerossl" } }
php_worker_max_requests / php_worker_idle membatasi umur worker.{
// PHP: aktifkan worker persistent (default "fastcgi")
"php_mode": "worker",
"php_worker_opcache": true,
"php_worker_max_requests": 500,
"php_worker_idle": "10m",
"php_worker_ram": 512, // RLIMIT_AS MiB per worker
"php_worker_cpu": 30, // RLIMIT_CPU detik
// Runtime non-PHP: worker persistent
"runtime_worker": true,
"runtime_workers": 2,
"runtime_worker_max_requests": 1000,
"runtime_worker_idle": "10m",
"runtime_worker_ram": 512,
// Node.js: default false = .js/.mjs/.cjs disajikan statis.
// Nyalakan true bila situs memang aplikasi Node (bukan CMS).
"nodejs": false
}
/* PHP · simpan index.php di webroot */
<?php
echo "<h1>Halo dari PHP " . PHP_VERSION . "</h1>";
?>
/* C · simpan halo.c, akses /halo.c (kompilasi otomatis) */
#include <stdio.h>
int main(void) {
printf("Content-Type: text/html\n\n");
printf("<h1>Halo dari C!</h1>");
return 0;
}
/* Go · simpan halo.go, akses /halo.go (compile di-cache) */
package main
import "fmt"
func main() {
fmt.Println("Content-Type: text/html")
fmt.Println()
fmt.Println("<h1>Halo dari Go!</h1>")
}
/* Python · simpan index.py */
print("Content-Type: text/html\n")
print("<h1>Halo dari Python!</h1>")
/* Node.js · simpan index.js, aktifkan "nodejs": true dulu */
const http = require("http");
http.createServer((req, res) => {
res.writeHead(200, { "Content-Type": "text/html" });
res.end("<h1>Halo dari Node.js!</h1>");
}).listen(process.env.PORT || 3000);
/* Bash · simpan halo.sh, akses /halo.sh (CGI) */
#!/bin/bash
echo "Content-Type: text/html"
echo
echo "<h1>Halo dari Bash!</h1>"
biru port 8080 (HTTP saja),biru port 8080 8443 (HTTP+HTTPS, HTTP/3 ikut),biru port - 8443 (HTTPS saja)http_port/https_port/h3_port di config/config.json, lalu restart penuh (port listener tidak bisa di-reload via SIGHUP).config/config.json, lalu systemctl restart biruss -tlnp | grep -E "8080|8443". $_SERVER['SERVER_PORT'] mengikuti otomatis.listen_ports di vhost.Tidak perlu menyentuh JSON. CLI biru membuat vhost, docroot, database, dan sertifikat HTTPS dalam sekali jalan.
Buat vhost + docroot baru dengan satu perintah & hapus beserta database-nya.
Node.js + worker persistent + watcher.
Blokir IP/CIDR selamanya (403) atau buka blokir; berlaku langsung tanpa restart.
Hidupkan HTTPS otomatis via ACME (Let's Encrypt / ZeroSSL), atau matikan dan buang cache sertifikatnya.
PHP + MariaDB, akun admin dibuat otomatis.biru app wp situs-saya.id
Node.js + MariaDB, reverse proxy.biru app ghost situs-saya.id
Java + MariaDB.biru app halo situs-saya.id
Python + Gunicorn + SQLite.biru app django situs-saya.id
PHP pure + admin.biru app grav situs-saya.id
PHP CodeIgniter + MariaDB.biru app sekolahku situs-saya.id
Lihat aplikasi yang bisa dipasang dan status kesiapannya.biru app list
Buat/hapus db+user, reset password, list, dan remote on/off — install otomatis bila belum ada.biru mysql add toko toko pass1234biru mysql public 203.0.113.5 (IP otomatis di-whitelist WAF)biru mysql private (whitelist dihapus)
API sama untuk Postgres, lengkap dengan auto-install OS-agnostic.biru pgsql add toko toko pass1234biru pgsql listbiru pgsql public 203.0.113.5 (IP otomatis di-whitelist WAF)
Auto-install via repo resmi (fallback codename untuk distro baru), auth authSource=admin.biru mongo add blog blog user1234biru mongo listbiru mongo public 203.0.113.5 (authorization dinyalakan otomatis + whitelist WAF)
--path <docroot> untuk lokasi kustom. Setelah itu tinggal biru ssl on <domain> untuk HTTPS.Biru tidak membatasi pada 9 method HTTP standar. Method WebDAV (PROPFIND, MKCOL, COPY, MOVE, LOCK, UNLOCK), PURGE, REPORT, MERGE, QUERY, CHECKOUT/CHECKIN, dan lain-lain diteruskan utuh ke engine — cocok untuk CalDAV/WebDAV, CMS, dan REST API modern. Tidak ada koneksi terputus untuk method yang tidak dikenal.
GETHEADPOSTPUTPATCHDELETECONNECTOPTIONSTRACE
Semua diproses penuh oleh pipeline Biru (deny-list, geoblock, WAF, rate limit, cache, engine PHP/CGI/statis/proxy). TRACE diblokir sejak awal.
PROPFINDMKCOLCOPYMOVELOCKUNLOCKPURGEREPORTMERGEQUERYCHECKOUTCHECKINUPDATE
Router yang dulu hanya mengenal 9 method diganti pipeline penuh — method ini diperlakukan sama seperti GET/POST.
| Method | Perilaku |
|---|---|
GET POST PUT PATCH DELETE CONNECT PURGE PROPFIND MKCOL COPY MOVE LOCK UNLOCK REPORT MERGE QUERY CHECKOUT CHECKIN UPDATE | Diteruskan ke engine — umumnya 200; body upload utuh termasuk >64 KB |
HEAD | 200 tanpa body (header sama dengan GET) |
OPTIONS | 204 + header Allow berisi daftar method lengkap |
TRACE | 405 — diblokir (anti refleksi request) |
PHP, Node, dan Python itu opsional, Biru tetap jalan sendiri. Install salah satu di bawah, filenya langsung bekerja tanpa restart.
Debian/Ubuntu
RHEL/Fedora
Alpine
Debian/Ubuntu
RHEL/Fedora
Arch
Debian/Ubuntu
RHEL/Fedora
Alpine
Debian/Ubuntu
RHEL/Fedora
FreeBSD
Debian/Ubuntu
RHEL/Fedora
Alpine
Urutan deteksi: Deno → Bun → TSX
Runtime WASM
toolchain 'X' is not installed on this host. Di lingkungan SLIME, interpreter diambil dari toolchain bawaan, tidak perlu install di host.Biru punya alat untuk menghentikan serangan yang sering terjadi, tanpa script atau cron tambahan.
Memindai tiap request untuk SQL injection, XSS, RCE, LFI, dan scanner. Mulai di mode "detect", ganti ke "block" saat siap.
Scanner background membaca access log dan memblokir penyerang otomatis. Tanpa cron, tanpa script, sudah ada di server.
Izinkan atau tolak pengunjung per negara, pakai database 251 negara bawaan, untuk IPv4 dan IPv6.
Membatasi request per detik untuk satu pengunjung, memperlambat brute-force dan serangan DDoS dasar.
Kode tiap situs jalan sebagai user sendiri di dalam chroot, bukan sebagai root. Satu situs tidak bisa baca file situs lain.
Sertifikat HTTPS dari Let's Encrypt atau ZeroSSL, diterbitkan dan diperbarui otomatis. Symlink keluar webroot = 403.
Kamu tidak perlu jadi administrator sistem. Installer mengurus semuanya.
Allow. TRACE diblokir (405)..htaccess ala Apache, jadi banyak situs lama bisa tinggal di-copy. PHP juga didukung dengan 18 versi.Tulis file, taruh di folder, buka browser. Itu saja.
Install Biru sekarang