Skip to content

Commit 92ff0dd

Browse files
LGA-3531: Add ModSec rules from CLA_Public (#151)
* Add ModSec config from CLA_Public * Add comments explaining the purpose of each rule
1 parent 6888c83 commit 92ff0dd

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

helm_deploy/laa-access-civil-legal-aid/templates/ingress.yaml

+7
Original file line numberDiff line numberDiff line change
@@ -22,10 +22,17 @@ metadata:
2222
{{- with .Values.ingress.annotations }}
2323
{{- toYaml . | nindent 4 }}
2424
{{- end }}
25+
# Some ModSec rules have been disabled to large numbers of false positives that impact standard user behaviour.
26+
# 942230 - SQL Injection - Directory Traversal Sequences
27+
# 930120 - Local File Inclusion
28+
# 933210 - PHP Injection
2529
nginx.ingress.kubernetes.io/enable-modsecurity: "true"
2630
nginx.ingress.kubernetes.io/modsecurity-snippet: |
2731
SecRuleEngine On
2832
SecDefaultAction "phase:2,pass,log,tag:github_team=laa-get-access"
33+
SecRuleRemoveById 942230
34+
SecRuleRemoveById 930120
35+
SecRuleRemoveById 933210
2936
spec:
3037
ingressClassName: {{ .Values.ingress.className }}
3138
{{- if .Values.ingress.tls }}

0 commit comments

Comments
 (0)