The Secure Way
Edge and WAF, the secure way
Web application firewalls that block instead of log, rate limits, blocklists and the edge in front of your app.
12 guides
- Coraza WAF with OWASP CRS v4 on Envoy Gateway, the secure wayRun the Coraza WAF with OWASP CRS v4 in Envoy Gateway: an EnvoyExtensionPolicy pinned by digest, fail-closed, blocking mode, and proof it blocks attacks.
- Fail-closed WASM filters pinned by digest, the secure wayLoad Envoy Wasm filters, such as a WAF, pinned by sha256 and failing closed: what Envoy and Envoy Gateway do when the module changes, and why fail-open is dangerous.
- IP blocklists with Envoy Gateway SecurityPolicy, the secure wayBlock IP ranges at Envoy Gateway with a SecurityPolicy that really matches the client: the right numTrustedHops, the XFF trap, and tested proof of each case.
- Multi-region edge PoPs on Kubernetes, the secure wayRun edge points of presence as small Kubernetes clusters with Envoy Gateway: identical policy from Git, per-PoP certificates, health-checked DNS, and no shared keys.
- OWASP CRS paranoia levels and false positives, the secure wayRaise OWASP CRS paranoia levels without blocking real users: detection paranoia level first, then narrow rule exclusions by path, parameter and rule ID.
- Protecting an identity-provider admin console at the edge, the secure wayKeep an identity provider's admin console off the internet while login stays public: Envoy Gateway route split, allowlist, and tests against path tricks.
- Rate limiting login endpoints on Envoy Gateway, the secure wayRate limit a login endpoint on Envoy Gateway so a query string or a trailing slash cannot skip it: a dedicated route, a per-IP global limit, a local backstop.
- Real client IPs with Proxy Protocol v2, the secure wayPass real client IPs from a TCP load balancer to Envoy with PROXY protocol v2, and stop anyone who reaches Envoy directly from forging their address.
- Upstream TLS from the edge with a pinned CA, the secure wayEncrypt and authenticate the edge-to-backend hop: BackendTLSPolicy with your own CA and hostname, why Envoy without a trusted CA verifies nothing, and tests.
- WAF audit logs without leaking credentials, the secure wayStop Coraza and ModSecurity audit logs from storing bearer tokens, cookies and passwords: which audit parts leak, safer parts, and redaction for matched data.
- WAF auto-ban across edge PoPs, the secure wayTurn WAF blocks into a shared, expiring IP ban list for every Envoy Gateway edge PoP, without banning your load balancer, yourself, or routes by accident.
- WAF rules for AI-agent credential and dev-server probes, the secure wayBlock probes for .env files, cloud keys, AI coding-agent configs and Vite dev-server paths like /@fs/ at the edge, with two tested Coraza rules on top of CRS.
T Academy
Every guide here is taught hands-on in H2-CPQE Edge and Post-Quantum Networking: a real host in your browser, and every objective checked on the machine.
Start free