Sign inSign up

anhtn512/caddy-waf

By anhtn512

•Updated over 2 years ago

Caddy x Coraza web application firewall for protecting container services

Image
Security
Web servers
0

100

anhtn512/caddy-waf repository overview

https://github.com/anhtn512/caddy-waf⁠

# Set Caddy release tag
ARG CADDY_TAG="2.7"

# Use official Caddy builder image
FROM caddy:"${CADDY_TAG}-builder" as builder-caddy

# Build Caddy with Coraza
RUN --mount=type=cache,target=/go,id=caddy \
  xcaddy build --with github.com/corazawaf/coraza-caddy

# Use official caddy builder image to get Core Rule Set
FROM caddy:"${CADDY_TAG}-builder" as builder-crs

# Set OWASP ModSecurity core rule set release tag to check out
# Available tags are on the GitHub releases page here: https://github.com/coreruleset/coreruleset/tags
ARG CRS_TAG="v4.0.0-rc1"

# Get OWASP ModSecurity Core Rule Set and main configuration file
RUN --mount=type=cache,target=/var/tmp,id=crs \
  set -eux; \
  # Only retrieve and extract rule set if not existing due to cache layer
  if [ ! -d "/var/tmp/owasp-crs" ]; \
  then \
    # Get rule set archive
    wget -q -O "/var/tmp/crs-${CRS_TAG}.tar.gz" "https://github.com/coreruleset/coreruleset/archive/refs/tags/${CRS_TAG}.tar.gz"; \
    # Extract rule set
    mkdir /var/tmp/owasp-crs; \
    tar x -z \
      --strip-components=1 \
      -f "/var/tmp/crs-${CRS_TAG}.tar.gz" \
      -C /var/tmp/owasp-crs \
    ; \
  fi; \
  # Create directory structure for Coraza
  mkdir -p \
    # Main configuration directory
    /opt/coraza/config \
    # Additional rules directory (not used yet)
    /opt/coraza/rules \
    # User configuration directory
    /opt/coraza/config.d \
    # User rule directory
    /opt/coraza/rules.d \
    # Rule/configuration overrides
    /opt/coraza/overrides \
  ; \
  # Copy rule set into rules dir
  cp -r /var/tmp/owasp-crs/rules /opt/coraza/owasp-crs; \
  # Copy CRS setup file into config dir
  cp /var/tmp/owasp-crs/crs-setup.conf.example /opt/coraza/config/crs-setup.conf

# Switch to official Caddy container
FROM caddy:"$CADDY_TAG"

# Copy newly built Caddy binary from builder-caddy
COPY --from=builder-caddy /usr/bin/caddy /usr/bin/caddy

# Copy out Coraza configuration files and rules from builder-caddy
COPY --from=builder-crs /opt/coraza /opt/coraza```

Tag summary

Content type

Image

Digest

sha256:69f0173b4…

Size

32.2 MB

Last updated

over 2 years ago

docker pull anhtn512/caddy-waf:2.7