- 
                Notifications
    
You must be signed in to change notification settings  - Fork 140
 
Add enhancement proposal for NAP WAF integration #3398
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
          
     Merged
      
      
    
                
     Merged
            
            
          Conversation
  
    
      This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
      Learn more about bidirectional Unicode characters
    
  
  
    
    
              
                    sjberman
  
              
              reviewed
              
                  
                    May 22, 2025 
                  
              
              
            
            
8d4fea5    to
    df7f6ad      
    Compare
  
    
              
                    sjberman
  
              
              reviewed
              
                  
                    May 27, 2025 
                  
              
              
            
            
df7f6ad    to
    762f57f      
    Compare
  
    
              
                    salonichf5
  
              
              reviewed
              
                  
                    May 28, 2025 
                  
              
              
            
            
              
                    sjberman
  
              
              approved these changes
              
                  
                    May 28, 2025 
                  
              
              
            
            
              
                    salonichf5
  
              
              reviewed
              
                  
                    May 28, 2025 
                  
              
              
            
            
              
                    salonichf5
  
              
              approved these changes
              
                  
                    May 28, 2025 
                  
              
              
            
            
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great work Ciara 🚀
| 
           @ciarams87, can you get @CVanF5 approval as well?  | 
    
fa0f095    to
    721b712      
    Compare
  
    
              
                    CVanF5
  
              
              approved these changes
              
                  
                    Jun 5, 2025 
                  
              
              
            
            
06a70c4    to
    0017e4b      
    Compare
  
    0017e4b    to
    6311060      
    Compare
  
    
    
  nowjean 
      pushed a commit
        to nowjean/nginx-gateway-fabric
      that referenced
      this pull request
    
      Jun 14, 2025 
    
    
      
  
    
      
    
  
* Add enhancement proposal for NAP WAF integration * Change proposal to use inherited policies * Add status conditions section * Remove redundant phrase * Add polling mechanism to proposal * Add sequence diagram and more detail on status conditions * Single targetRef and other clarifications * Change WafPolicy to WAFPolicy
    
  nowjean 
      pushed a commit
        to nowjean/nginx-gateway-fabric
      that referenced
      this pull request
    
      Jun 14, 2025 
    
    
      
  
    
      
    
  
* Add enhancement proposal for NAP WAF integration * Change proposal to use inherited policies * Add status conditions section * Remove redundant phrase * Add polling mechanism to proposal * Add sequence diagram and more detail on status conditions * Single targetRef and other clarifications * Change WafPolicy to WAFPolicy
    
  nowjean 
      pushed a commit
        to nowjean/nginx-gateway-fabric
      that referenced
      this pull request
    
      Jun 14, 2025 
    
    
      
  
    
      
    
  
* Add enhancement proposal for NAP WAF integration * Change proposal to use inherited policies * Add status conditions section * Remove redundant phrase * Add polling mechanism to proposal * Add sequence diagram and more detail on status conditions * Single targetRef and other clarifications * Change WafPolicy to WAFPolicy
  
    Sign up for free
    to join this conversation on GitHub.
    Already have an account?
    Sign in to comment
  
      Labels
      
    documentation
  Improvements or additions to documentation 
  
    enhancement-proposal
  Enhancement Proposal issue 
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
Proposed changes
Write a clear and concise description that helps reviewers understand the purpose and impact of your changes. Use the
following format:
Problem: As a maintainer of NGF
I want a design to describe what the UX and high level implementation details I need for WAF v5
So that I can implement that design later to build the feature in NGF.
Solution: Create an enhancement proposal detailing the architecture of the proposed design. Note this does not go into any code specific implementation details or design, this proposal is focused on the overall architecture and approach.
Testing: Deployed the multi-container NGINX pod with NAP WAF installed as detailed in the proposal, and ensured WAF protection was running against the traffic. I have not tested any of the Policy pulling mechanisms detailed in the proposal.
Please focus on (optional): If you any specific areas where you would like reviewers to focus their attention or provide
specific feedback, add them here.
Closes #3341
Checklist
Before creating a PR, run through this checklist and mark each as complete.
Release notes
If this PR introduces a change that affects users and needs to be mentioned in the release notes,
please add a brief note that summarizes the change.