Explorar o código

Adds Exceptions for Teleport WAF

To be tagged v5.1.11
Fred Damstra [afs macbook] %!s(int64=3) %!d(string=hai) anos
pai
achega
17097f3e36
Modificáronse 1 ficheiros con 6 adicións e 1 borrados
  1. 6 1
      base/teleport-single-instance/waf.tf

+ 6 - 1
base/teleport-single-instance/waf.tf

@@ -31,8 +31,13 @@ module "waf" {
   excluded_rules_AWSManagedRulesUnixRuleSet = [
   ]
 
+  excluded_rules_AWSManagedRulesLinuxRuleSet = [
+    "LFI_URIPATH", # /web/config.js needed
+  ]
+
   excluded_rules_AWSManagedRulesCommonRuleSet = [
-    "SizeRestrictions_BODY",
+    "SizeRestrictions_BODY", # for SAML
+    "EC2MetaDataSSRF_BODY",  # for SAML
   ]
 
   # These are passed through and should be the same for module