WAF for Small Ecosystems
Concepts
The single front door to a self-hosted environment: what it inspects, what it terminates, and wha...
Why This Design
A single edge host that terminates public TLS, inspects every request, and forwards only what pas...
Architecture
Where the edge sits and what it hands off to. The WAF is one boundary in a layered defense, and u...
Standing Up the Edge
The reverse proxy and public TLS, before any inspection is added. This is the baseline every publ...
Adding Inspection
Attaching application-layer inspection to the reverse proxy. Standing up the edge gave you a prox...
Operating It
A WAF is not a set-and-forget install. It is a control you have to be able to see working, tune w...
Lessons Learned
The lessons I've learned from running a single-edge WAF in a self-hosted environment. Run learnin...