Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions google_fastly_waf/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,7 @@ module "fastly_stage" {
| <a name="input_conditions"></a> [conditions](#input\_conditions) | List of Fastly conditions to create (REQUEST, RESPONSE or CACHE). | <pre>list(object({<br/> name = string # required, unique<br/> statement = string # VCL conditional expression<br/> type = string # one of: REQUEST, RESPONSE, CACHE<br/> priority = optional(number) # lower runs first, default 10<br/> }))</pre> | `[]` | no |
| <a name="input_ddos_protection"></a> [ddos\_protection](#input\_ddos\_protection) | Optional DDoS Protection configuration for the Fastly service product enablement. | <pre>object({<br/> enabled = bool<br/> mode = string<br/> })</pre> | `null` | no |
| <a name="input_ddos_protection_alert"></a> [ddos\_protection\_alert](#input\_ddos\_protection\_alert) | Optional Slack alerting for Fastly DDoS Protection. When set, the module creates a Slack `fastly_integration` and a `fastly_alert` on the `ddos_protection_requests_detect_count` stats metric that notifies the channel behind the webhook. Intended to be paired with `ddos_protection` being enabled. Set to `null` (the default) to create no alerting resources. | <pre>object({<br/> enabled = optional(bool, true)<br/> slack_webhook_secret = string<br/> threshold = optional(number, 1)<br/> period = optional(string, "5m")<br/> description = optional(string)<br/> })</pre> | `null` | no |
| <a name="input_default_object_ttl"></a> [default\_object\_ttl](#input\_default\_object\_ttl) | Default TTL (in seconds) applied in vcl\_fetch to cacheable responses that arrive from origin without any cache headers (no Expires, Surrogate-Control max-age, or Cache-Control s-maxage/max-age). Lower it to cap how long header-less responses are cached. | `number` | `3600` | no |
| <a name="input_domains"></a> [domains](#input\_domains) | A list of domains | `list(any)` | `[]` | no |
| <a name="input_extra_log_fields"></a> [extra\_log\_fields](#input\_extra\_log\_fields) | Extra columns to add to the BigQuery logs table, on top of the base schema in logging/bq\_schema.json. Each entry adds both the log-format field and the matching table column, so the two cannot drift. `expression` is a bare Fastly VCL expression -- no `%{}V` wrapper and no `%%` escaping. The module always wraps it in `json.escape()` and always emits a quoted `STRING` / `NULLABLE` column, so a value should never break the JSON log line. Nesting works, e.g. `if(req.http.X-Foo, req.http.X-Foo, "none")`. There is no type knob: cast in SQL if you need a number (the base schema already stores `response\_status` as `STRING`). Append-only. BigQuery cannot reorder or drop columns, so add new entries at the end of the list and never remove one -- to retire a field, stop populating it and leave the column. This writes into the shared WAF log dataset, which is retained for 90 days and broadly readable. Never log credentials, cookies, authorization headers, or request bodies. | <pre>list(object({<br/> name = string<br/> expression = string<br/> description = optional(string, "")<br/> }))</pre> | `[]` | no |
| <a name="input_https_redirect_enabled"></a> [https\_redirect\_enabled](#input\_https\_redirect\_enabled) | n/a | `bool` | `true` | no |
Expand Down
1 change: 1 addition & 0 deletions google_fastly_waf/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -243,6 +243,7 @@ resource "fastly_service_vcl" "default" {
environment = var.environment,
https_redirect_enabled = var.https_redirect_enabled,
cache_header = var.cache_header,
default_object_ttl = var.default_object_ttl,
legacy_edge_deployment = var.legacy_edge_deployment
}
)
Expand Down
11 changes: 11 additions & 0 deletions google_fastly_waf/variables.tf
Original file line number Diff line number Diff line change
Expand Up @@ -163,6 +163,17 @@ variable "cache_header" {
description = "A cache header to check to toggle cache lookup"
}

variable "default_object_ttl" {
type = number
default = 3600
description = <<-EOT
Default TTL (in seconds) applied in vcl_fetch to cacheable responses that
arrive from origin without any cache headers (no Expires, Surrogate-Control
max-age, or Cache-Control s-maxage/max-age). Lower it to cap how long
header-less responses are cached.
EOT
}

variable "bot_management" {
description = "Bot Management configuration for the Fastly service product enablement."
type = object({
Expand Down
2 changes: 1 addition & 1 deletion google_fastly_waf/vcl/main.vcl.tftpl
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@ sub vcl_fetch {

# If no TTL has been provided in the response headers, set a default
if (!beresp.http.Expires && !beresp.http.Surrogate-Control ~ "max-age" && !beresp.http.Cache-Control ~ "(?:s-maxage|max-age)") {
set beresp.ttl = 3600s;
set beresp.ttl = ${default_object_ttl}s;

# Apply a longer default TTL for images processed using Image Optimizer
if (req.http.X-Fastly-Imageopto-Api) {
Expand Down
Loading