Sentinel in practice

Edge intelligence for modern Caddy stacks.

Sentinel’s 3,358+ lines of Go code wrap Caddy with geo policies, anomaly detection, and DevOps-grade observability. Here’s how customers are using it.

SaaS control planes

Regional access policies

B2B SaaS teams add `block_countries` rules for management routes to satisfy export restrictions without building another proxy tier.

  • Example: a data residency product restricts admin logins to EU IPs while keeping customer APIs global.

Customer-tier protections

Usage-based SaaS plans call Sentinel’s Admin API to toggle anomaly detection for premium tenants when suspicious spikes occur.

API-first platforms

Federated API gateways

Fintechs embed Sentinel in Caddy-based gateways to detect path-specific anomalies. AlertDeliveryManager routes high-severity alerts to PagerDuty and lower tiers to Slack.

Developer ecosystem sandboxes

Developer portals with ephemeral tenants use Sentinel to throttle or block abusive API keys, surfacing Prometheus metrics for each workspace.

Content & media

Streaming launches

Entertainment networks run Sentinel alongside Caddy auto TLS to absorb scraper spikes and block known bad ASNs minutes after a show premiers.

CDN origin shielding

News publishers put Sentinel in front of origin servers to provide structured logs and metrics that feed into their observability stack.