Global InfraGlobal Infra Cloud
WAF

Policy

Terraform reference for Policy.

Schema Properties

PropertyTypeDescription
listen_fqdn
Required
stringFully qualified domain name the WAF listens on (the public-facing VIP hostname).
Examples:waf-myapp-acme.offnet.sbx.ginfra.net
name
RequiredForceNew
stringName of the WAF instance, used as the MoldAPI job name and as the first DNS label of the listen FQDN (waf-<name>-<tenant>...). Must be alphanumeric with '-' or '_' separators, 1-40 characters. Immutable after creation.
Examples:my-service
security_config
Required
objectSecurity-related configuration: OWASP Core Rule Set tuning, ModSecurity engine settings and custom rules.
target_fqdn
Required
stringFully qualified domain name of the backend service the WAF reverse-proxies to.
Examples:myapp.services.acme.sbx.eu.ginfra.net
target_port
Required
integerTCP port of the backend service.
Examples:443
target_ssl
booleanWhether the WAF connects to the backend over TLS. Defaults to true.
Examples:true
vhost_config
Required
objectApache virtual-host configuration for the reverse proxy.
resource "gi_waf_policy" "example" {  attributes = {    listen_fqdn     = "waf-myapp-acme.offnet.sbx.ginfra.net"    name            = "my-service"    target_fqdn     = "myapp.services.acme.sbx.eu.ginfra.net"    target_port     = 443    security_config = {}    vhost_config    = {}  }}

Usage Notes