Skip to content

Commit 516b516

Browse files
authored
Merge pull request #164 from bihius/feat/m1-03-coraza-spoa-bundle
feat(waf): add Coraza SPOA CRS bundle
2 parents 1964e81 + ed74ee6 commit 516b516

18 files changed

Lines changed: 209 additions & 29 deletions

‎.dockerignore‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
**
2+
3+
!configs/
4+
!configs/coraza/
5+
!configs/coraza/**
6+
!deploy/
7+
!deploy/docker/
8+
!deploy/docker/coraza.Dockerfile
9+
10+
configs/coraza/crs/.git

‎.gitmodules‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
[submodule "configs/coraza/crs"]
2+
path = configs/coraza/crs
3+
url = https://github.com/coreruleset/coreruleset.git

‎Makefile‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
COMPOSE_FILE := deploy/docker/docker-compose.yml
22
ENV_FILE := deploy/docker/.env
33

4-
.PHONY: dev down logs ps seed
4+
.PHONY: dev down logs ps seed coraza-build
55

66
dev:
77
docker-compose -f $(COMPOSE_FILE) --env-file $(ENV_FILE) up --build
@@ -17,3 +17,6 @@ ps:
1717

1818
seed:
1919
docker-compose -f $(COMPOSE_FILE) --env-file $(ENV_FILE) exec backend /app/.venv/bin/python scripts/seed_admin.py
20+
21+
coraza-build:
22+
docker build -f deploy/docker/coraza.Dockerfile -t guard-proxy/coraza-spoa:dev .

‎README.commands.md‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -52,7 +52,8 @@ tcpdump -i lo -A -s 0 port 9000 # Debug SPOE traffic
5252
```bash
5353
cp deploy/docker/.env.example deploy/docker/.env # Create env file for compose
5454
docker-compose -f deploy/docker/docker-compose.yml --env-file deploy/docker/.env config
55-
make dev # Start all services (attached, with build)
55+
make dev # Start all services (runs backend migrations, attached, with build)
56+
make coraza-build # Build the pinned Coraza SPOA + CRS image
5657
make ps # Show service status
5758
make logs # Follow all service logs
5859
make down # Stop stack and remove volumes

‎README.md‎

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -63,8 +63,10 @@ Or view [milestones](https://github.com/bihius/guard-proxy/milestones)
6363
- `make dev`
6464
3. Access services:
6565
- Frontend: `http://localhost:3000`
66-
- API via HAProxy: `http://localhost:8080`
67-
- Backend docs: `http://localhost:8080/docs`
66+
- API via HAProxy: `http://localhost:8080` with `Host: app.local`
67+
- Backend health via HAProxy: `curl -H 'Host: app.local' http://localhost:8080/health`
68+
4. Optional WAF smoke test:
69+
- `curl -i -H 'Host: app.local' "http://localhost:8080/?id=1%27%20OR%20%271%27=%271"` should return `403 Forbidden`
6870

6971
Use `make down` to stop containers and remove volumes.
7072

‎configs/coraza/README.md‎

Lines changed: 48 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
# Coraza configuration
2+
3+
This directory contains the hand-written M1 Coraza SPOA and OWASP CRS bundle.
4+
M2 will replace these seed files with generated configuration derived from the
5+
policy database.
6+
7+
## First-time setup
8+
9+
The `crs/` directory is a git submodule. If you cloned the repository without
10+
`--recurse-submodules` (or your CI checkout did not initialise submodules), run:
11+
12+
```sh
13+
git submodule update --init --recursive
14+
```
15+
16+
## Pinned versions
17+
18+
- Coraza SPOA image: `ghcr.io/corazawaf/coraza-spoa:0.6.1`
19+
- OWASP Core Rule Set: `v4.25.0`, pinned as the `configs/coraza/crs` git
20+
submodule
21+
22+
## Files
23+
24+
| File | Purpose |
25+
| --- | --- |
26+
| `coraza-spoa.yaml` | `coraza-spoa` daemon configuration and default application mapping |
27+
| `coraza.conf` | Baseline Coraza directives and CRS includes |
28+
| `crs-setup.conf` | CRS paranoia and anomaly-scoring defaults |
29+
| `crs/` | Pinned OWASP CRS 4.x submodule |
30+
31+
## Defaults
32+
33+
- Request inspection is enabled with `SecRuleEngine On`.
34+
- Response body inspection is disabled for M1, matching ADR-007.
35+
- Blocking paranoia level is `1`.
36+
- Inbound and outbound anomaly thresholds are `5`.
37+
- Relevant audit events are written as JSON to `/var/log/coraza/audit.json`.
38+
39+
## Updating CRS
40+
41+
```sh
42+
git -C configs/coraza/crs fetch --tags
43+
git -C configs/coraza/crs checkout v4.x.y
44+
```
45+
46+
After updating, also change the pinned CRS version in
47+
`deploy/docker/coraza.Dockerfile`, `configs/coraza/crs-setup.conf`, and this
48+
README.

‎configs/coraza/coraza-spoa.yaml‎

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
# Coraza SPOA service configuration for the Docker Compose stack.
2+
3+
bind: 0.0.0.0:9000
4+
log_level: info
5+
log_file: /dev/stdout
6+
log_format: console
7+
8+
default_application: default
9+
10+
applications:
11+
- name: default
12+
directives: |
13+
Include /etc/coraza/coraza.conf
14+
response_check: false
15+
transaction_ttl_ms: 60000
16+
log_level: info
17+
log_file: /dev/stdout
18+
log_format: console

‎configs/coraza/coraza.conf‎

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# Baseline Coraza/CRS configuration for the M1 Docker Compose stack.
2+
#
3+
# This file is included by coraza-spoa.yaml for the default application.
4+
# M2 will generate per-policy Coraza configuration from the database; until
5+
# then these defaults provide a reproducible CRS-backed WAF.
6+
7+
SecRuleEngine On
8+
9+
SecRequestBodyAccess On
10+
SecResponseBodyAccess Off
11+
12+
SecAuditEngine RelevantOnly
13+
SecAuditLogType Serial
14+
SecAuditLogFormat JSON
15+
SecAuditLog /var/log/coraza/audit.json
16+
SecAuditLogParts ABIJDEFHZ
17+
18+
SecDefaultAction "phase:1,log,auditlog,pass"
19+
SecDefaultAction "phase:2,log,auditlog,pass"
20+
21+
Include /etc/coraza/crs-setup.conf
22+
Include /etc/coraza/crs/rules/*.conf

‎configs/coraza/crs‎

Submodule crs added at aabf675

‎configs/coraza/crs-setup.conf‎

Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
# Guard Proxy CRS 4.x baseline.
2+
#
3+
# Keep this file small and explicit. The full upstream reference lives in
4+
# configs/coraza/crs/crs-setup.conf.example.
5+
6+
SecAction \
7+
"id:900000,\
8+
phase:1,\
9+
pass,\
10+
nolog,\
11+
tag:'OWASP_CRS',\
12+
ver:'OWASP_CRS/4.25.0',\
13+
setvar:tx.blocking_paranoia_level=1"
14+
15+
SecAction \
16+
"id:900005,\
17+
phase:1,\
18+
pass,\
19+
nolog,\
20+
tag:'OWASP_CRS',\
21+
ver:'OWASP_CRS/4.25.0',\
22+
setvar:tx.detection_paranoia_level=1"
23+
24+
SecAction \
25+
"id:900110,\
26+
phase:1,\
27+
pass,\
28+
nolog,\
29+
tag:'OWASP_CRS',\
30+
ver:'OWASP_CRS/4.25.0',\
31+
setvar:tx.inbound_anomaly_score_threshold=5,\
32+
setvar:tx.outbound_anomaly_score_threshold=5"
33+
34+
SecAction \
35+
"id:900990,\
36+
phase:1,\
37+
pass,\
38+
nolog,\
39+
tag:'OWASP_CRS',\
40+
ver:'OWASP_CRS/4.25.0',\
41+
setvar:tx.crs_setup_version=4250"

0 commit comments

Comments
 (0)