import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Associates a WAFv2 Rule Group (custom or managed) with a Web ACL by adding a rule that references the Rule Group. Use this resource to apply the rules defined in a Rule Group to a Web ACL without duplicating rule definitions. * * This resource supports both: * * - **Custom Rule Groups**: User-created rule groups that you manage within your AWS account * - **Managed Rule Groups**: Pre-configured rule groups provided by AWS or third-party vendors * * > **Warning:** Verify the rule names in your `ruleActionOverride`s carefully. With managed rule groups, WAF silently ignores any override that uses an invalid rule name. With customer-owned rule groups, invalid rule names in your overrides will cause web ACL updates to fail. An invalid rule name is any name that doesn't exactly match the case-sensitive name of an existing rule in the rule group. * * > **Warning:** Using this resource will cause the associated Web ACL resource to show configuration drift in the `rule` argument unless you add `lifecycle { ignoreChanges = [rule] }` to the Web ACL resource configuration. This is because this resource modifies the Web ACL's rules outside of the Web ACL resource's direct management. * * > **Note:** This resource creates a rule within the Web ACL that references the entire Rule Group. The rule group's individual rules are evaluated as a unit when requests are processed by the Web ACL. * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * // Web ACL must use lifecycle.ignore_changes to prevent drift from this resource * const example = new aws.wafv2.WebAcl("example", { * defaultAction: { * allow: {}, * }, * visibilityConfig: { * cloudwatchMetricsEnabled: true, * metricName: "example-web-acl", * sampledRequestsEnabled: true, * }, * name: "example-web-acl", * scope: "REGIONAL", * }, { * ignoreChanges: ["rules"], * }); * // Associate a custom rule group * const exampleWebAclRuleGroupAssociation = new aws.wafv2.WebAclRuleGroupAssociation("example", { * ruleGroupReference: { * arn: exampleAwsWafv2RuleGroup.arn, * }, * ruleName: "example-rule-group-rule", * priority: 100, * webAclArn: example.arn, * }); * ``` * ### Managed Rule Group * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * managedRuleGroup: { * name: "AWSManagedRulesCommonRuleSet", * vendorName: "AWS", * }, * ruleName: "aws-common-rule-set", * priority: 50, * webAclArn: exampleAwsWafv2WebAcl.arn, * }); * ``` * ### Managed Rule Group With Version * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * managedRuleGroup: { * name: "AWSManagedRulesCommonRuleSet", * vendorName: "AWS", * version: "Version_1.0", * }, * ruleName: "aws-common-rule-set-versioned", * priority: 60, * webAclArn: exampleAwsWafv2WebAcl.arn, * }); * ``` * ### Managed Rule Group With Rule Action Overrides * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * managedRuleGroup: { * ruleActionOverrides: [ * { * actionToUse: { * count: { * customRequestHandling: { * insertHeaders: [{ * name: "X-RFI-Override", * value: "counted", * }], * }, * }, * }, * name: "GenericRFI_BODY", * }, * { * actionToUse: { * captcha: {}, * }, * name: "SizeRestrictions_BODY", * }, * ], * name: "AWSManagedRulesCommonRuleSet", * vendorName: "AWS", * }, * ruleName: "aws-common-rule-set-with-overrides", * priority: 70, * webAclArn: exampleAwsWafv2WebAcl.arn, * }); * ``` * ### Managed Rule Group With Managed Rule Group Configs * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * managedRuleGroup: { * managedRuleGroupConfigs: { * awsManagedRulesAcfpRuleSet: { * requestInspection: { * emailField: { * identifier: "/email", * }, * passwordField: { * identifier: "/password", * }, * phoneNumberFields: { * identifiers: [ * "/phone1", * "/phone2", * ], * }, * addressFields: { * identifiers: [ * "home", * "work", * ], * }, * usernameField: { * identifier: "/username", * }, * payloadType: "JSON", * }, * creationPath: "/creation", * registrationPagePath: "/registration", * }, * }, * name: "AWSManagedRulesACFPRuleSet", * vendorName: "AWS", * }, * visibilityConfig: { * cloudwatchMetricsEnabled: true, * metricName: "friendly-metric-name", * sampledRequestsEnabled: true, * }, * ruleName: "acfp-ruleset-with-rule-config", * priority: 70, * webAclArn: exampleAwsWafv2WebAcl.arn, * }); * ``` * ### Custom Rule Group With Override Action * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * ruleGroupReference: { * arn: exampleAwsWafv2RuleGroup.arn, * }, * ruleName: "example-rule-group-rule", * priority: 100, * webAclArn: exampleAwsWafv2WebAcl.arn, * overrideAction: "count", * }); * ``` * ### Custom Rule Group With Rule Action Overrides * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * ruleGroupReference: { * ruleActionOverrides: [ * { * actionToUse: { * count: { * customRequestHandling: { * insertHeaders: [{ * name: "X-Geo-Block-Override", * value: "counted", * }], * }, * }, * }, * name: "geo-block-rule", * }, * { * actionToUse: { * captcha: { * customRequestHandling: { * insertHeaders: [{ * name: "X-Rate-Limit-Override", * value: "captcha-required", * }], * }, * }, * }, * name: "rate-limit-rule", * }, * ], * arn: exampleAwsWafv2RuleGroup.arn, * }, * ruleName: "example-rule-group-rule", * priority: 100, * webAclArn: exampleAwsWafv2WebAcl.arn, * }); * ``` * ### CloudFront Web ACL * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.wafv2.WebAclRuleGroupAssociation("example", { * ruleGroupReference: { * arn: exampleAwsWafv2RuleGroup.arn, * }, * ruleName: "cloudfront-rule-group-rule", * priority: 50, * webAclArn: exampleAwsWafv2WebAcl.arn, * }); * ``` * * ## Import * * Using `pulumi import`, import WAFv2 web ACL custom rule group associations using `WebACLARN,RuleName,RuleGroupType,RuleGroupARN`, where `RuleGroupType` is `custom`. For example: * * ```sh * $ pulumi import aws:wafv2/webAclRuleGroupAssociation:WebAclRuleGroupAssociation example "arn:aws:wafv2:us-east-1:123456789012:regional/webacl/example-web-acl/12345678-1234-1234-1234-123456789012,example-rule-group-rule,custom,arn:aws:wafv2:us-east-1:123456789012:regional/rulegroup/example-rule-group/87654321-4321-4321-4321-210987654321" * ``` * * Using `pulumi import`, import WAFv2 web ACL managed rule group associations using `WebACLARN,RuleName,RuleGroupType,VendorName:RuleGroupName[:Version]`, where `RuleGroupType` is `managed`. For example: * * ```sh * $ pulumi import aws:wafv2/webAclRuleGroupAssociation:WebAclRuleGroupAssociation managed_example "arn:aws:wafv2:us-east-1:123456789012:regional/webacl/example-web-acl/12345678-1234-1234-1234-123456789012,aws-common-rule-set,managed,AWS:AWSManagedRulesCommonRuleSet" * ``` */ export declare class WebAclRuleGroupAssociation extends pulumi.CustomResource { /** * Get an existing WebAclRuleGroupAssociation resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: WebAclRuleGroupAssociationState, opts?: pulumi.CustomResourceOptions): WebAclRuleGroupAssociation; /** * Returns true if the given object is an instance of WebAclRuleGroupAssociation. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is WebAclRuleGroupAssociation; /** * Managed Rule Group configuration. One of `ruleGroupReference` or `managedRuleGroup` is required. Conflicts with `ruleGroupReference`. See below. */ readonly managedRuleGroup: pulumi.Output; /** * Override action for the rule group. Valid values are `none` and `count`. Defaults to `none`. When set to `count`, the actions defined in the rule group rules are overridden to count matches instead of blocking or allowing requests. */ readonly overrideAction: pulumi.Output; /** * Priority of the rule within the Web ACL. Rules are evaluated in order of priority, with lower numbers evaluated first. */ readonly priority: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Custom Rule Group reference configuration. One of `ruleGroupReference` or `managedRuleGroup` is required. Conflicts with `managedRuleGroup`. See below. */ readonly ruleGroupReference: pulumi.Output; /** * Name of the rule to create in the Web ACL that references the rule group. Must be between 1 and 128 characters. */ readonly ruleName: pulumi.Output; readonly timeouts: pulumi.Output; /** * Defines and enables Amazon CloudWatch metrics and web request sample collection. See below. */ readonly visibilityConfig: pulumi.Output; /** * ARN of the Web ACL to associate the Rule Group with. * * The following arguments are optional: */ readonly webAclArn: pulumi.Output; /** * Create a WebAclRuleGroupAssociation resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: WebAclRuleGroupAssociationArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering WebAclRuleGroupAssociation resources. */ export interface WebAclRuleGroupAssociationState { /** * Managed Rule Group configuration. One of `ruleGroupReference` or `managedRuleGroup` is required. Conflicts with `ruleGroupReference`. See below. */ managedRuleGroup?: pulumi.Input; /** * Override action for the rule group. Valid values are `none` and `count`. Defaults to `none`. When set to `count`, the actions defined in the rule group rules are overridden to count matches instead of blocking or allowing requests. */ overrideAction?: pulumi.Input; /** * Priority of the rule within the Web ACL. Rules are evaluated in order of priority, with lower numbers evaluated first. */ priority?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Custom Rule Group reference configuration. One of `ruleGroupReference` or `managedRuleGroup` is required. Conflicts with `managedRuleGroup`. See below. */ ruleGroupReference?: pulumi.Input; /** * Name of the rule to create in the Web ACL that references the rule group. Must be between 1 and 128 characters. */ ruleName?: pulumi.Input; timeouts?: pulumi.Input; /** * Defines and enables Amazon CloudWatch metrics and web request sample collection. See below. */ visibilityConfig?: pulumi.Input; /** * ARN of the Web ACL to associate the Rule Group with. * * The following arguments are optional: */ webAclArn?: pulumi.Input; } /** * The set of arguments for constructing a WebAclRuleGroupAssociation resource. */ export interface WebAclRuleGroupAssociationArgs { /** * Managed Rule Group configuration. One of `ruleGroupReference` or `managedRuleGroup` is required. Conflicts with `ruleGroupReference`. See below. */ managedRuleGroup?: pulumi.Input; /** * Override action for the rule group. Valid values are `none` and `count`. Defaults to `none`. When set to `count`, the actions defined in the rule group rules are overridden to count matches instead of blocking or allowing requests. */ overrideAction?: pulumi.Input; /** * Priority of the rule within the Web ACL. Rules are evaluated in order of priority, with lower numbers evaluated first. */ priority: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Custom Rule Group reference configuration. One of `ruleGroupReference` or `managedRuleGroup` is required. Conflicts with `managedRuleGroup`. See below. */ ruleGroupReference?: pulumi.Input; /** * Name of the rule to create in the Web ACL that references the rule group. Must be between 1 and 128 characters. */ ruleName: pulumi.Input; timeouts?: pulumi.Input; /** * Defines and enables Amazon CloudWatch metrics and web request sample collection. See below. */ visibilityConfig?: pulumi.Input; /** * ARN of the Web ACL to associate the Rule Group with. * * The following arguments are optional: */ webAclArn: pulumi.Input; } //# sourceMappingURL=webAclRuleGroupAssociation.d.ts.map