WAF
Policy
Terraform reference for Policy.
Schema Properties
| Property | Type | Description |
|---|---|---|
listen_fqdn Required | string | Fully qualified domain name the WAF listens on (the public-facing VIP hostname). Examples: waf-myapp-acme.offnet.sbx.ginfra.net |
name RequiredForceNew | string | Name of the WAF instance, used as the MoldAPI job name and as the first DNS label of the listen FQDN (waf-<name>-<tenant>...). Must be alphanumeric with '-' or '_' separators, 1-40 characters. Immutable after creation. Examples: my-service |
security_config Required | object | Security-related configuration: OWASP Core Rule Set tuning, ModSecurity engine settings and custom rules. |
target_fqdn Required | string | Fully qualified domain name of the backend service the WAF reverse-proxies to. Examples: myapp.services.acme.sbx.eu.ginfra.net |
target_port Required | integer | TCP port of the backend service. Examples: 443 |
target_ssl | boolean | Whether the WAF connects to the backend over TLS. Defaults to true. Examples: true |
vhost_config Required | object | Apache virtual-host configuration for the reverse proxy. |
resource "gi_waf_policy" "example" { attributes = { listen_fqdn = "waf-myapp-acme.offnet.sbx.ginfra.net" name = "my-service" target_fqdn = "myapp.services.acme.sbx.eu.ginfra.net" target_port = 443 security_config = {} vhost_config = {} }}