What is Kestrel ShieldWAF?
Kestrel built Kestrel ShieldWAF for workloads that outgrow DIY setups: consistent latency, honest limits, and one-line failover between zones. The service bills by the minute, scales vertically and horizontally, and exposes every metric through an open API. Kestrel operates it as a fully managed service: patching, capacity, and failover are handled upstream, while access controls and spend alerts stay in your hands.
Key features
- Sub-minute provisioning through console, CLI, or API
- Per-second billing with no minimum commitment
- Role-based access control with audit logging
- 99.95% or better regional SLA with service credits
- Granular metrics exported to your own monitoring stack
Typical use cases
- Data pipelines that need predictable throughput at a fixed cost
- SaaS platforms scaling from first customer to full estate
- Development teams standardizing on one infrastructure API
- Disaster recovery sites kept warm without idle hardware costs
Why Kestrel?
Kestrel publishes list prices for every region and never gates core capabilities behind enterprise-only tiers. Capacity is pre-provisioned, so the performance you benchmark in a sandbox is the performance you get in production. And because egress rates are flat, the bill at the end of the month matches the estimate you made at the start.
Getting started
Create an account, pick a region, and the default configuration is live in under a minute. The quickstart walks through your first deployment in about ten minutes, and the managed Terraform module turns the same setup into code you can review.