Skip to content

Support for WAF access logsΒ #2439

@takeshi-hatamoto

Description

@takeshi-hatamoto

Is the feature request related to the issue?
When trying to configure WAFv2 access logging via ACK (wafv2.services.k8s.aws/v1alpha1), Kinesis Firehose integration CloudWatch Logs log group, and S3 bucket is currently not supported.
Since AWS WAFv2 requires Kinesis Firehose, CloudWatch Logs log group, and S3 bucket as logging destinations for access logs, it is not possible to fully manage WAFv2 access logging via ACK unless it is manually configured outside Kubernetes.

About your preferred solution
I would like ACK to support the ability to configure Kinesis Firehose, s3 buckets, and CloudWatch Logs log groups as the destination for WAFv2 access logging in the WebACLLLoggingConfiguration resource.

Associate logs with webacl similar to [https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/wafv2_web_acl_logging_configuration] Add support for

Metadata

Metadata

Assignees

Labels

kind/new-fieldCategorizes issue or PR as related to a new fieldservice/wafv2Indicates issues or PRs that are related to wafv2-controller.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions