Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AWS Shield Advanced: Discussion and ADR entry #6649

Open
sj-williams opened this issue Jan 9, 2025 · 0 comments
Open

AWS Shield Advanced: Discussion and ADR entry #6649

sj-williams opened this issue Jan 9, 2025 · 0 comments

Comments

@sj-williams
Copy link
Contributor

Background

We have some outstanding tickets following investigation into AWS Shield Advanced that are not viable without a decision in place for how Cloud Platform will provide WAF services in the future:

#5730
#5731
#6001

Investigation work has proven that implementing AWS Shield Advanced WAF features requires major changes not only to CP infrastructure (ingress controllers design change and full rebuild of LBs), but also a total change of how users/services implement WAF and rules.

We need to make a decision as to whether we stick to using ModSec, or opt for Shield Advanced and commit to putting together a roadmap for introducing this major change.

This ticket exists to cover:

  • Having a discussion around ModSec vs Shield, and making sure that we have agreed to a firm decision on which route we take as an outcome of that discussion
  • Recording this decision as an ADR
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: Todo
Development

No branches or pull requests

1 participant