Files
acdl/modules/l1/waf
Jon Chery bb3ac7c74d
acdl-ci / Lint (pull_request) Successful in 8s
acdl-ci / Platform check-only (offline) (pull_request) Successful in 24s
acdl-modules-lifecycle / CI VPC apply (pull_request) Successful in 40s
acdl-ci / Test (pull_request) Successful in 4m1s
acdl-modules-lifecycle / L1 lifecycle (alb) (pull_request) Failing after 1m54s
acdl-modules-lifecycle / L1 lifecycle (cloudfront) (pull_request) Successful in 9m20s
acdl-modules-lifecycle / L1 lifecycle (ecr) (pull_request) Successful in 2m38s
acdl-modules-lifecycle / L1 lifecycle (ecs-cluster) (pull_request) Successful in 2m58s
acdl-modules-lifecycle / L1 lifecycle (iam-role) (pull_request) Successful in 2m37s
acdl-modules-lifecycle / L1 lifecycle (ecs-service) (pull_request) Failing after 5m13s
acdl-modules-lifecycle / L1 lifecycle (rds) (pull_request) Failing after 1m18s
acdl-modules-lifecycle / L1 lifecycle (kms-key) (pull_request) Successful in 2m54s
acdl-modules-lifecycle / L1 lifecycle (s3) (pull_request) Successful in 2m55s
acdl-modules-lifecycle / L1 lifecycle (vpc) (pull_request) Successful in 2m49s
acdl-modules-lifecycle / L1 lifecycle (uptime) (pull_request) Failing after 6m3s
acdl-modules-lifecycle / L1 lifecycle (waf) (pull_request) Successful in 3m11s
acdl-modules-lifecycle / CI VPC destroy (pull_request) Failing after 20m40s
fix(P60): WAF scope case + VPC modify DependencyViolation
Two module defects found in the prior live matrix run (3000, SHA
a55752e2) that hadn't been fixed:

1. WAF: `scope: cloudfront` in complex example failed with "expected
   scope to be one of [CLOUDFRONT REGIONAL], got cloudfront". AWS
   requires uppercase. Added `scope = upper(var.scope)` in locals.tf
   so the module is resilient to either casing, and fixed the complex
   example to use CLOUDFRONT.

2. VPC: simple→complex modify tried to replace the VPC (CIDR changed
   10.0.0.0/16 → 10.50.0.0/16, which is ForceNew) while subnets/IGW/
   route tables still referenced it → DependencyViolation. Fixed the
   complex example to use the same CIDR (10.0.0.0/16) so terraform
   modifies in-place (adds a 3rd AZ subnet, updates tags). Also added
   create_before_destroy lifecycle on the VPC as a defensive measure.

Regression: 479 passed, 5 deselected. 24 example contracts resolve.

---ci---
project: acdl
phase: P60
milestone: v1.11
status: execute
---/ci---
2026-07-28 20:13:07 +00:00
..

waf — WAFv2 Web ACL

Module kind: primitive | Version: 1.0.0

A WAFv2 Web ACL scoped to CloudFront. It applies managed rule groups by default and can be associated with a CloudFront distribution to filter traffic before it reaches the origin. CloudFront-scoped Web ACLs are always created in us-east-1.

Resources

Resource Type Purpose
webacl aws_wafv2_web_acl WAFv2 Web ACL with managed rules

Inputs

Name Type Required Default Description
name string yes Name of the Web ACL
scope string no cloudfront Scope of the Web ACL (default cloudfront for CloudFront associations)
default_action string no allow Default action (default allow)
rules string no Optional custom rules as JSON (default: managed rules only)
region string yes AWS region (CloudFront-scoped WAF is always us-east-1; the adapter ignores this for cloudfront scope)

Outputs

Name Type Description
web_acl_arn arn The WAF Web ACL ARN

Usage

{
  "id": "waf",
  "type": "aws:wafv2:webacl",
  "module": "waf@1.0.0",
  "inputs": {
    "name": "acdl-static-assets-waf",
    "scope": "cloudfront",
    "default_action": "allow",
    "region": "us-east-1"
  }
}

The web_acl_arn output is typically wired as a ref: expression into the cloudfront primitive's waf_web_acl_arn input inside a module composition (see modules/l2/static-assets).

Compliance extension points

  • Rate limiting — add a rate-based rule to cap requests per IP (SOC2 CC6.1, DORA operational resilience).
  • Geo blocking — add a geo-match statement to block/allow countries for data-residency compliance (GDPR Art.44, SOC2 CC6.1).
  • Custom rules — add custom rule statements for application-specific filtering (e.g. block SQLi/IP allow-lists) (SOC2 CC6.1).
  • Logging — enable WAF access logging to S3/CloudWatch/Kinesis for auditability (SOC2 CC7.2, DORA audit trail).

Examples

Validated example contracts are in examples/. The platform-test pipeline validates them against schemas/contract.schema.json.

Simple

A minimal deployment:

examples/simple.yml

environment: dev
id: waf
infrastructure:
  waf:
    inputs:
      name: my-waf
      region: us-east-1
    version: 1.0.0
name: waf-firewall

Complex

A production deployment with optional inputs:

examples/complex.yml

environment: dev
id: waf
infrastructure:
  waf:
    inputs:
      default_action: allow
      name: my-production-waf
      region: us-east-1
      scope: cloudfront
    version: 1.0.0
name: waf-firewall

Versioning

1.0.0 — interface MAJOR, behavior MINOR, lifecycle PATCH. MAJOR bumps require a new registry entry (immutable publication); old entries enter a 12-month deprecation window.