瀏覽代碼

Adds Exceptions for Teleport WAF

To be tagged v5.1.11
Fred Damstra [afs macbook] 3 年之前
父節點
當前提交
17097f3e36
共有 1 個文件被更改,包括 6 次插入1 次删除
  1. 6 1
      base/teleport-single-instance/waf.tf

+ 6 - 1
base/teleport-single-instance/waf.tf

@@ -31,8 +31,13 @@ module "waf" {
   excluded_rules_AWSManagedRulesUnixRuleSet = [
   ]
 
+  excluded_rules_AWSManagedRulesLinuxRuleSet = [
+    "LFI_URIPATH", # /web/config.js needed
+  ]
+
   excluded_rules_AWSManagedRulesCommonRuleSet = [
-    "SizeRestrictions_BODY",
+    "SizeRestrictions_BODY", # for SAML
+    "EC2MetaDataSSRF_BODY",  # for SAML
   ]
 
   # These are passed through and should be the same for module