File tree Expand file tree Collapse file tree 7 files changed +28
-2
lines changed Expand file tree Collapse file tree 7 files changed +28
-2
lines changed Original file line number Diff line number Diff line change @@ -22,6 +22,10 @@ metadata:
2222 alb.ingress.kubernetes.io/listen-ports : ' {{ .Values.alb.listenPorts | default "[{\"HTTP\":80},{\"HTTPS\":443}]" }}'
2323 alb.ingress.kubernetes.io/certificate-arn : " {{ .Values.alb.certificateArn }}"
2424 alb.ingress.kubernetes.io/ssl-redirect : ' 443'
25+ # Enable WAF
26+ {{- if .Values.alb.enableWaf.enabled }}
27+ alb.ingress.kubernetes.io/waf-acl-arn : " {{ .Values.alb.enableWaf.wafAclArn }}"
28+ {{- end }}
2529 {{- end }}
2630spec :
2731 ingressClassName : {{ .Values.ingressClassName }}
Original file line number Diff line number Diff line change @@ -22,6 +22,10 @@ metadata:
2222 alb.ingress.kubernetes.io/listen-ports : ' {{ .Values.alb.listenPorts | default "[{\"HTTP\":80},{\"HTTPS\":443}]" }}'
2323 alb.ingress.kubernetes.io/certificate-arn : " {{ .Values.alb.certificateArn }}"
2424 alb.ingress.kubernetes.io/ssl-redirect : ' 443'
25+ # Enable WAF
26+ {{- if .Values.alb.enableWaf.enabled }}
27+ alb.ingress.kubernetes.io/waf-acl-arn : " {{ .Values.alb.enableWaf.wafAclArn }}"
28+ {{- end }}
2529 {{- end }}
2630spec :
2731 ingressClassName : {{ .Values.ingressClassName }}
Original file line number Diff line number Diff line change @@ -22,6 +22,10 @@ metadata:
2222 alb.ingress.kubernetes.io/listen-ports : ' {{ .Values.alb.listenPorts | default "[{\"HTTP\":80},{\"HTTPS\":443}]" }}'
2323 alb.ingress.kubernetes.io/certificate-arn : " {{ .Values.alb.certificateArn }}"
2424 alb.ingress.kubernetes.io/ssl-redirect : ' 443'
25+ # Enable WAF
26+ {{- if .Values.alb.enableWaf.enabled }}
27+ alb.ingress.kubernetes.io/waf-acl-arn : " {{ .Values.alb.enableWaf.wafAclArn }}"
28+ {{- end }}
2529 {{- end }}
2630spec :
2731 ingressClassName : {{ .Values.ingressClassName }}
Original file line number Diff line number Diff line change @@ -22,6 +22,10 @@ metadata:
2222 alb.ingress.kubernetes.io/listen-ports : ' {{ .Values.alb.listenPorts | default "[{\"HTTP\":80},{\"HTTPS\":443}]" }}'
2323 alb.ingress.kubernetes.io/certificate-arn : " {{ .Values.alb.certificateArn }}"
2424 alb.ingress.kubernetes.io/ssl-redirect : ' 443'
25+ # Enable WAF
26+ {{- if .Values.alb.enableWaf.enabled }}
27+ alb.ingress.kubernetes.io/waf-acl-arn : " {{ .Values.alb.enableWaf.wafAclArn }}"
28+ {{- end }}
2529 {{- end }}
2630spec :
2731 ingressClassName : {{ .Values.ingressClassName }}
Original file line number Diff line number Diff line change @@ -22,6 +22,10 @@ metadata:
2222 alb.ingress.kubernetes.io/listen-ports : ' {{ .Values.alb.listenPorts | default "[{\"HTTP\":80},{\"HTTPS\":443}]" }}'
2323 alb.ingress.kubernetes.io/certificate-arn : " {{ .Values.alb.certificateArn }}"
2424 alb.ingress.kubernetes.io/ssl-redirect : ' 443'
25+ # Enable WAF
26+ {{- if .Values.alb.enableWaf.enabled }}
27+ alb.ingress.kubernetes.io/waf-acl-arn : " {{ .Values.alb.enableWaf.wafAclArn }}"
28+ {{- end }}
2529 {{- end }}
2630spec :
2731 ingressClassName : {{ .Values.ingressClassName }}
Original file line number Diff line number Diff line change @@ -22,6 +22,10 @@ metadata:
2222 alb.ingress.kubernetes.io/listen-ports : ' {{ .Values.alb.listenPorts | default "[{\"HTTP\":80},{\"HTTPS\":443}]" }}'
2323 alb.ingress.kubernetes.io/certificate-arn : " {{ .Values.alb.certificateArn }}"
2424 alb.ingress.kubernetes.io/ssl-redirect : ' 443'
25+ # # Enable WAF
26+ {{- if .Values.alb.enableWaf.enabled }}
27+ alb.ingress.kubernetes.io/waf-acl-arn : " {{ .Values.alb.enableWaf.wafAclArn }}"
28+ {{- end }}
2529 {{- end }}
2630spec :
2731 ingressClassName : {{ .Values.ingressClassName }}
Original file line number Diff line number Diff line change @@ -46,8 +46,10 @@ createClusterIssuer: false
4646ingressClassNameType : " alb" # Type can be alb or nlb
4747ingressClassName : alb # nginx, nginx-nlb, alb
4848alb :
49- certificateArn : " arn:aws:acm:us-east-1:618380242247:certificate/498e3dc0-843b-4c98-8d41-861775806e86"
50-
49+ certificateArn : " arn:aws:acm:us-east-1:1234567890:certificate/abcdeffff-843b-4c98-8d41-abcdeffff"
50+ enableWaf :
51+ enabled : false
52+ wafAclArn : arn:aws:wafv2:us-east-1:123456789:regional/webacl/webacl-alb/abcdeffff-ddddd-ddddd-bbbb-abcdeffff
5153# Domain that is pointed to the clusterIP
5254# You will need to create an A record like *.osmseed.example.com pointed to the ClusterIP
5355# Then, the cluster configuration will setup services at their respective subdomains:
You can’t perform that action at this time.
0 commit comments