Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: add ngwaf to pypi instances #172

Merged
merged 8 commits into from
Sep 27, 2024
Merged
Show file tree
Hide file tree
Changes from 6 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
80 changes: 80 additions & 0 deletions terraform/.terraform.lock.hcl

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

15 changes: 15 additions & 0 deletions terraform/config.tf
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,13 @@ variable "x_pypi_admin_token" {
sensitive = true
}

## NGWAF
variable "ngwaf_token" {
type = string
description = "Secret token for the NGWAF API."
sensitive = true
}

terraform {
cloud {
organization = "psf"
Expand Down Expand Up @@ -77,3 +84,11 @@ provider "aws" {
provider "fastly" {
api_key = var.credentials["fastly"]
}

provider "sigsci" {
alias = "firewall"
corp = "python"
email = "[email protected]"
auth_token = var.ngwaf_token
fastly_api_key = var.credentials["fastly"]
}
14 changes: 14 additions & 0 deletions terraform/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -109,6 +109,13 @@ module "pypi" {

fastly_endpoints = local.fastly_endpoints
domain_map = local.domain_map

# NGWAF
ngwaf_site_name = "pypi-prod"
ngwaf_email = "[email protected]"
ngwaf_token = var.ngwaf_token
activate_ngwaf_service = false
edge_security_dictionary = "Edge_Security"
}

module "test-pypi" {
Expand Down Expand Up @@ -136,6 +143,13 @@ module "test-pypi" {

fastly_endpoints = local.fastly_endpoints
domain_map = local.domain_map

# NGWAF
ngwaf_site_name = "pypi-test"
ngwaf_email = "[email protected]"
ngwaf_token = var.ngwaf_token
activate_ngwaf_service = true
edge_security_dictionary = "Edge_Security"
}

module "file-hosting" {
Expand Down
6 changes: 5 additions & 1 deletion terraform/versions.tf
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,11 @@ terraform {
}
fastly = {
source = "fastly/fastly"
version = "1.1.2"
version = "5.13.0"
}
sigsci = {
source = "signalsciences/sigsci"
version = "3.3.0"
}
}
required_version = ">= 1.1.8"
Expand Down
57 changes: 57 additions & 0 deletions terraform/warehouse/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,12 @@ variable "fastly_toppops_enabled" { type = bool }
variable "fastly_endpoints" { type = map(any) }
variable "domain_map" { type = map(any) }

variable "ngwaf_site_name" { type = string }
variable "ngwaf_email" { type = string }
variable "ngwaf_token" { type = string }
variable "activate_ngwaf_service" { type = bool }
variable "edge_security_dictionary" { type = string }


locals {
apex_domain = length(split(".", var.domain)) > 2 ? false : true
Expand Down Expand Up @@ -226,6 +232,57 @@ resource "fastly_service_vcl" "pypi" {
type = "RESPONSE"
statement = "req.http.Fastly-Client-IP == \"127.0.0.1\" && req.http.Fastly-Client-IP != \"127.0.0.1\""
}

# NGWAF
dynamic "dictionary" {
for_each = var.activate_ngwaf_service ? [1] : []
content {
name = var.edge_security_dictionary
force_destroy = true
}
}

dynamic "dynamicsnippet" {
for_each = var.activate_ngwaf_service ? [1] : []
content {
name = "ngwaf_config_init"
type = "init"
priority = 0
}
}

dynamic "dynamicsnippet" {
for_each = var.activate_ngwaf_service ? [1] : []
content {
name = "ngwaf_config_miss"
type = "miss"
priority = 9000
}
}

dynamic "dynamicsnippet" {
for_each = var.activate_ngwaf_service ? [1] : []
content {
name = "ngwaf_config_pass"
type = "pass"
priority = 9000
}
}

dynamic "dynamicsnippet" {
for_each = var.activate_ngwaf_service ? [1] : []
content {
name = "ngwaf_config_deliver"
type = "deliver"
priority = 9000
}
}

lifecycle {
ignore_changes = [
product_enablement,
]
}
}


Expand Down
57 changes: 57 additions & 0 deletions terraform/warehouse/ngwaf.tf
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
provider "sigsci" {
# if i dont add this it errors: Provider configuration not present
alias = "firewall"
corp = "python"
email = "[email protected]"
auth_token = var.ngwaf_token
}

resource "fastly_service_dictionary_items" "edge_security_dictionary_items" {
count = var.activate_ngwaf_service ? 1 : 0
service_id = fastly_service_vcl.pypi.id
dictionary_id = one([for d in fastly_service_vcl.pypi.dictionary : d.dictionary_id if d.name == var.edge_security_dictionary])
items = {
Enabled : "100"
}
}

resource "fastly_service_dynamic_snippet_content" "ngwaf_config_snippets" {
for_each = var.activate_ngwaf_service ? toset(["init", "miss", "pass", "deliver"]) : []
service_id = fastly_service_vcl.pypi.id
snippet_id = one([for d in fastly_service_vcl.pypi.dynamicsnippet : d.snippet_id if d.name == "ngwaf_config_${each.key}"])
content = "### Terraform managed ngwaf_config_${each.key}"
manage_snippets = false
}

# NGWAF Edge Deployment on SignalSciences.net
resource "sigsci_edge_deployment" "ngwaf_edge_site_service" {
count = var.activate_ngwaf_service ? 1 : 0
provider = sigsci.firewall
site_short_name = var.ngwaf_site_name
}

resource "sigsci_edge_deployment_service" "ngwaf_edge_service_link" {
count = var.activate_ngwaf_service ? 1 : 0
provider = sigsci.firewall
site_short_name = var.ngwaf_site_name
fastly_sid = fastly_service_vcl.pypi.id
activate_version = var.activate_ngwaf_service
percent_enabled = 100
depends_on = [
sigsci_edge_deployment.ngwaf_edge_site_service,
fastly_service_vcl.pypi,
fastly_service_dictionary_items.edge_security_dictionary_items,
fastly_service_dynamic_snippet_content.ngwaf_config_snippets,
]
}

resource "sigsci_edge_deployment_service_backend" "ngwaf_edge_service_backend_sync" {
count = var.activate_ngwaf_service ? 1 : 0
provider = sigsci.firewall
site_short_name = var.ngwaf_site_name
fastly_sid = fastly_service_vcl.pypi.id
fastly_service_vcl_active_version = fastly_service_vcl.pypi.active_version
depends_on = [
sigsci_edge_deployment_service.ngwaf_edge_service_link,
]
}
7 changes: 6 additions & 1 deletion terraform/warehouse/versions.tf
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,12 @@ terraform {
source = "hashicorp/aws"
}
fastly = {
source = "fastly/fastly"
source = "fastly/fastly"
version = ">= 5.13.0"
}
sigsci = {
source = "signalsciences/sigsci"
version = "3.3.0"
}
}
required_version = ">= 0.13"
Expand Down