Global WAF logging/blocking

Problem to solve

Please reference the MVC Issue

Intended users

Please reference the MVC Issue

Further details

Please reference the MVC Issue

Proposal

  1. If the ModSecurity WAF is installed and enabled, allow users to toggle the global default setting for WAF between logging and blocking modes. By default it will be set to logging

Permissions and Security

Users must be a Maintainer or Owner on the project to have access to the Operations -> Kubernetes page. No additional permissions are required.

Experience:

Cluster level settings:

#198727 (closed)

Cluster edge cases:

#198727 (closed)

Documentation

  1. Documentation will be added on how to globally set the WAF to Logging and Blocking modes

What is the type of buyer?

GitLab Core

Links / references

Edited by Lindsay Kerr