Directories
¶
| Path | Synopsis |
|---|---|
|
api
|
|
|
seclang/v1beta1
Package v1beta1 contains API Schema definitions for the seclang v1beta1 API group.
|
Package v1beta1 contains API Schema definitions for the seclang v1beta1 API group. |
|
subresources/v1alpha1
Package v1alpha1 holds Probe result types for the aggregated subresources.kubewaf.io API group.
|
Package v1alpha1 holds Probe result types for the aggregated subresources.kubewaf.io API group. |
|
waf/v1beta1
Package v1beta1 contains API Schema definitions for the waf v1beta1 API group.
|
Package v1beta1 contains API Schema definitions for the waf v1beta1 API group. |
|
crs-converter
command
|
|
|
probe-test-server
command
Command probe-test-server is the kubeWAF probe Test HTTP Server (go-coraza).
|
Command probe-test-server is the kubeWAF probe Test HTTP Server (go-coraza). |
|
subresource-api
command
Command subresource-api is the kubeWAF Subresource API Server (aggregated extension for subresources.kubewaf.io).
|
Command subresource-api is the kubeWAF Subresource API Server (aggregated extension for subresources.kubewaf.io). |
|
internal
|
|
|
coraza/crsdata
Package crsdata embeds stock OWASP CRS *.data phrase lists used by @pmFromFile for operator-side Coraza validation (WithRootFS).
|
Package crsdata embeds stock OWASP CRS *.data phrase lists used by @pmFromFile for operator-side Coraza validation (WithRootFS). |
|
dataplane/config
Package config builds portable Proxy-Wasm configuration for the WAF engine (ModSecurity) and the optional Challenge (PoW) filter.
|
Package config builds portable Proxy-Wasm configuration for the WAF engine (ModSecurity) and the optional Challenge (PoW) filter. |
|
dataplane/ecds
Package ecds implements a gRPC Extension Config Discovery Service (ECDS) that serves Wasm filter configurations to Envoy proxies.
|
Package ecds implements a gRPC Extension Config Discovery Service (ECDS) that serves Wasm filter configurations to Envoy proxies. |
|
dataplane/engine
Package engine catalogs Proxy-Wasm modules integrated with kubeWAF: modsecurity-proxy-wasm (WAF) and challenge/pow-proxy-wasm.
|
Package engine catalogs Proxy-Wasm modules integrated with kubeWAF: modsecurity-proxy-wasm (WAF) and challenge/pow-proxy-wasm. |
|
dataplane/extensionserver
Package extensionserver implements the Envoy Gateway Extension Server hooks that inject ECDS filter stubs and the kubewaf_ecds cluster into generated xDS.
|
Package extensionserver implements the Envoy Gateway Extension Server hooks that inject ECDS filter stubs and the kubewaf_ecds cluster into generated xDS. |
|
dataplane/index
Package index provides field indexes and reverse maps from SecRule/RuleSet back to WAFs so controllers do not requeue every WAF on every rule change.
|
Package index provides field indexes and reverse maps from SecRule/RuleSet back to WAFs so controllers do not requeue every WAF on every rule change. |
|
dataplane/observability
Package observability maps Envoy Wasm stats to the kubewaf.waf.* catalog and converts OTel access-log records into waf.eval span fixtures.
|
Package observability maps Envoy Wasm stats to the kubewaf.waf.* catalog and converts OTel access-log records into waf.eval span fixtures. |
|
dataplane/pipeline
Package pipeline is the single build+publish path shared by the leader WAF controller and every-replica dataplane sync.
|
Package pipeline is the single build+publish path shared by the leader WAF controller and every-replica dataplane sync. |
|
dataplane/slot
Package slot defines the platform filter-slot registry (Istio EnvoyFilter, Cilium CEC, Envoy Gateway extension index).
|
Package slot defines the platform filter-slot registry (Istio EnvoyFilter, Cilium CEC, Envoy Gateway extension index). |
|
dataplane/slot/cilium
Package cilium installs CiliumEnvoyConfig slots that attach ECDS config_discovery HTTP filters to Cilium Envoy (Gateway + Service L7).
|
Package cilium installs CiliumEnvoyConfig slots that attach ECDS config_discovery HTTP filters to Cilium Envoy (Gateway + Service L7). |
|
dataplane/slot/istio
Package istio installs EnvoyFilter slots that point Istio gateways at kubeWAF ECDS.
|
Package istio installs EnvoyFilter slots that point Istio gateways at kubeWAF ECDS. |
|
dataplane/sync
Package sync keeps the local ECDS snapshot and Envoy Gateway extension index warm on EVERY operator replica (not only the leader).
|
Package sync keeps the local ECDS snapshot and Envoy Gateway extension index warm on EVERY operator replica (not only the leader). |
|
dataplane/wasmserve
Package wasmserve hosts one or more Proxy-Wasm binaries over HTTP so Envoy can fetch them for ECDS filters (ModSecurity, Challenge/PoW).
|
Package wasmserve hosts one or more Proxy-Wasm binaries over HTTP so Envoy can fetch them for ECDS filters (ModSecurity, Challenge/PoW). |
|
dataplane/xdsutil
Package xdsutil builds shared Envoy xDS fragments (clusters, HTTP filter stubs).
|
Package xdsutil builds shared Envoy xDS fragments (clusters, HTTP filter stubs). |
|
probeassemble
Package probeassemble builds Coraza-safe SecLang documents for probe evaluation.
|
Package probeassemble builds Coraza-safe SecLang documents for probe evaluation. |
|
probetest
Package probetest implements go-coraza load/process/unload for probe evaluation.
|
Package probetest implements go-coraza load/process/unload for probe evaluation. |
|
probetest/api
Package api holds internal EvalRequest/EvalResponse wire types for the Subresource API Server → Test HTTP Server hop (K25).
|
Package api holds internal EvalRequest/EvalResponse wire types for the Subresource API Server → Test HTTP Server hop (K25). |
|
seclang
Package seclang holds shared SecRule render/validate helpers used by the SecRule controller, webhooks (optional), and dataplane assembly.
|
Package seclang holds shared SecRule render/validate helpers used by the SecRule controller, webhooks (optional), and dataplane assembly. |
|
subresourceapi
Package subresourceapi is the capability-agnostic Subresource API Server shell plus v1 probe handlers.
|
Package subresourceapi is the capability-agnostic Subresource API Server shell plus v1 probe handlers. |
|
test
|
|
Click to show internal directories.
Click to hide internal directories.