Skip to content

Commit 8e62bc9

Browse files
authored
CDPT-1958 Enable modsec in non-prod namespaces (#787)
1 parent 7a7083f commit 8e62bc9

File tree

2 files changed

+10
-2
lines changed

2 files changed

+10
-2
lines changed

config/kubernetes/qa/ingress.yml

+5-1
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,12 @@ metadata:
1515
location ~* \.(php|cgi|xml)$ {
1616
deny all; access_log off;
1717
}
18+
nginx.ingress.kubernetes.io/enable-modsecurity: "true"
19+
nginx.ingress.kubernetes.io/modsecurity-snippet: |
20+
SecRuleEngine On
21+
SecDefaultAction "phase:2,pass,log,tag:github_team=central-digital-product-team,tag:namespace=disclosure-checker-qa"
1822
spec:
19-
ingressClassName: default
23+
ingressClassName: modsec
2024
tls:
2125
- hosts:
2226
- disclosure-checker-qa.apps.live.cloud-platform.service.justice.gov.uk

config/kubernetes/staging/ingress.yml

+5-1
Original file line numberDiff line numberDiff line change
@@ -15,8 +15,12 @@ metadata:
1515
location ~* \.(php|cgi|xml)$ {
1616
deny all; access_log off;
1717
}
18+
nginx.ingress.kubernetes.io/enable-modsecurity: "true"
19+
nginx.ingress.kubernetes.io/modsecurity-snippet: |
20+
SecRuleEngine On
21+
SecDefaultAction "phase:2,pass,log,tag:github_team=central-digital-product-team,tag:namespace=disclosure-checker-staging"
1822
spec:
19-
ingressClassName: default
23+
ingressClassName: modsec
2024
tls:
2125
- hosts:
2226
- disclosure-checker-staging.apps.live.cloud-platform.service.justice.gov.uk

0 commit comments

Comments
 (0)