coraza-kubernetes-operator

module
v0.1.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Feb 25, 2026 License: Apache-2.0

README

CI RELEASE

Coraza Kubernetes Operator

Web Application Firewall (WAF) support for Kubernetes Gateways.

About

The Coraza Kubernetes Operator (CKO) enables declarative management of Web Application Firewalls (WAF) on Kubernetes clusters. Users can deploy firewall engines which are attached to gateways, and rules which those engines enforce.

Coraza is used as the firewall engine.

Key Features
  • Engine API - declaratively manage WAF instances
  • RuleSet API - declaratively manage firewall rules
  • ModSecurity Seclang compatibility
Supported Integrations

The operator integrates with other tools to attach WAF instances to their gateways/proxies:

  • istio - Istio integration ✅ Currently Supported (ingress Gateway only)
  • wasm - WebAssembly deployment ✅ Currently Supported

Note: Only Istio+WASM is supported currently.

Architecture

The CKO's ruleset controller responds to RuleSet resources by validating and compiling the rules (e.g. list of ConfigMap resources containing the Seclang rules), which gets emitted to the RuleSet cache.

Note: Currently, only Seclang rules are supported.

Warning: Hosting or providing any packaged rules is an explicit non-goal of this project. Users must supply their own rules.

The keys for the cache are the namespace/name of the RuleSet, allowing the compiled set of rules to be polled from a cache server hosting the cache.

Note: All RuleSets and rules are restricted to same-namespace currently.

The engine controller responds to Engine resources by deploying the Coraza engine according to the type and mode provided, and attaching it to a Gateway.

Note: For example: if the type is istio and the mode is wasm, it will attach Coraza to an Istio Gateway, loading it via a WASM module.

Engine resources target a RuleSet to indicate the firewall rules that will be applied to all Gateway traffic. Poll intervals for RuleSets can be set to enable automatic and live rule updates on running Engines.

cko-architecture-diagram

Documentation

Documentation is available in the wiki.

Contributing

Contributions are welcome!

See CONTRIBUTING.md.

License

Apache License 2.0 - see LICENSE.

Directories

Path Synopsis
api
v1alpha1
Package v1alpha1 contains API Schema definitions for the waf v1alpha1 API group.
Package v1alpha1 contains API Schema definitions for the waf v1alpha1 API group.
internal
controller
Package controller implements Kubernetes controllers for WAF resources.
Package controller implements Kubernetes controllers for WAF resources.
rulesets/cache
Package cache provides in-memory caching for WAF rulesets.
Package cache provides in-memory caching for WAF rulesets.
test
utils
Package utils provides testing utilities for integration and unit tests.
Package utils provides testing utilities for integration and unit tests.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL