Просмотр исходного кода

Merge pull request #490 from mdr-engineering/feature/ftd_MSOCI-2207_EnableWAFEnforcementForTeleport

Enables enforcement for teleport waf
Frederick Damstra 3 лет назад
Родитель
Сommit
df3b772b2b
1 измененных файлов с 9 добавлено и 9 удалено
  1. 9 9
      base/teleport-single-instance/waf.tf

+ 9 - 9
base/teleport-single-instance/waf.tf

@@ -14,15 +14,15 @@ module "waf" {
 
   # Set to 'false' to set as 'count only'
   block_settings = {
-    default                               = false, # Default action. False = count
-    custom                                = false, # XDR Custom Rules. False = count
-    admin                                 = false, # /admin folder
-    AWSManagedRulesCommonRuleSet          = false,
-    AWSManagedRulesAmazonIpReputationList = false,
-    AWSManagedRulesKnownBadInputsRuleSet  = false,
-    AWSManagedRulesSQLiRuleSet            = false,
-    AWSManagedRulesLinuxRuleSet           = false,
-    AWSManagedRulesUnixRuleSet            = false,
+    default                               = true, # Default action. False = count
+    custom                                = true, # XDR Custom Rules. False = count
+    admin                                 = true, # /admin folder
+    AWSManagedRulesCommonRuleSet          = true,
+    AWSManagedRulesAmazonIpReputationList = true,
+    AWSManagedRulesKnownBadInputsRuleSet  = true,
+    AWSManagedRulesSQLiRuleSet            = true,
+    AWSManagedRulesLinuxRuleSet           = true,
+    AWSManagedRulesUnixRuleSet            = true,
   }
 
   excluded_rules_AWSManagedRulesSQLiRuleSet = [