Skip to main content

Entity reference

All eight entities are ordinary Otoroshi entities: full CRUD in the admin UI, the admin API, import/export, and Kubernetes CRDs. They share the API group waf.extensions.cloud-apim.com/v1 and carry the usual _loc, id, name, description, tags and metadata fields.

WafConfig​

waf-configs · waf.extensions.cloud-apim.com/WafConfig

FieldTypeDefault
enabledbooleantrue
blockbooleantrue
rulesetsstring[][] — WafRuleset ids, applied in order before the inline rules
rulesstring[][] — inline rules, applied last
inspect_input_bodybooleantrue
input_body_limitnumber | nullnull — meaning the 2 MB default, never unlimited
inspect_output_bodybooleantrue
output_body_limitnumber | nullnull — same default
output_body_mimetypesstring[][] — matched on the media type alone, wildcards allowed
oversize_body_actioninspect_prefix | rejectinspect_prefix
decompressed_input_body_limitnumber | nullnull — 64 MiB; 0 turns it off
max_input_compression_rationumber | nullnull — 100; 0 turns it off
undecodable_body_actionreject | inspect_rawreject

WafRuleset​

waf-rulesets · waf.extensions.cloud-apim.com/WafRuleset

FieldTypeDefault
enabledbooleantrue — a disabled ruleset contributes nothing to the configs referencing it
rulesstring[][]

A named body of SecLang that several configs can share. See rulesets.

ThreatFeed​

threat-feeds · waf.extensions.cloud-apim.com/ThreatFeed

FieldTypeDefault
enabledbooleantrue
urlstring""
methodstringGET
headersobject{}
follow_redirectsbooleantrue
formatcidr_lines | csv | json_array | json_path | mispcidr_lines
optionsobject{}
refresh_interval_secondsnumber3600
timeout_millisnumber30000
max_entriesnumber2000000
weightnumber50
actionblock | monitormonitor
tagstringfeed:<id>
catalog_refstring | nullnull

Format options​

FormatOptionDefault
csvcolumn0
csvseparator,
csvskip_headerfalse
json_arrayfield—
json_pathpathrequired

CrowdSecBouncer​

crowdsec-bouncers · waf.extensions.cloud-apim.com/CrowdSecBouncer

FieldTypeDefault
enabledbooleantrue
lapi_urlstringhttp://127.0.0.1:8080
api_keystring""
poll_interval_secondsnumber10
timeout_millisnumber10000
scopesstring[]["ip", "range"]
origins_filterstring[][]
weightnumber90
actionblock | monitorblock
tagstringcrowdsec
push_enabledbooleanfalse
push_machine_idstring""
push_passwordstring""
push_scenariostringcloud-apim/otoroshi-reputation
push_interval_secondsnumber10
push_max_batchnumber50
push_with_decisionbooleanfalse
push_decision_durationstring4h
push_waf_detectionsbooleanfalse
push_waf_monitoredbooleanfalse

AsnDatabase​

asn-databases · waf.extensions.cloud-apim.com/AsnDatabase

FieldTypeDefault
enabledbooleantrue
urlstringhttps://iptoasn.com/data/ip2asn-v4.tsv.gz
gzipbooleantrue
formatiptoasn_tsviptoasn_tsv
refresh_interval_secondsnumber86400
timeout_millisnumber120000
max_entriesnumber1500000
categoriesAsnCategory[]cdn (0), vpn (30), hosting (15)

AsnCategory​

FieldTypeDefault
namestring—
weightnumber0
actionblock | monitormonitor
tagstringasn:<name>
org_containsstring[][] — case-insensitive substrings of the organisation name
asnsnumber[][] — explicit AS numbers, matched first

The list is ordered: the first matching category wins. See ASN classification.

GeoDatabase​

geo-databases · waf.extensions.cloud-apim.com/GeoDatabase

FieldTypeDefault
enabledbooleantrue
urlstringhttps://download.db-ip.com/free/dbip-country-lite-{yyyy}-{MM}.mmdb.gz
usernamestring— · basic auth, the account id for MaxMind
passwordstring— · basic auth, the license key for MaxMind
headersobject{}
refresh_interval_secondsnumber86400
timeout_millisnumber300000
max_size_mbnumber512 — once extracted
attributionstringIP Geolocation by DB-IP
attribution_urlstringhttps://db-ip.com

Any MaxMind DB file, raw, gzipped or in a tar.gz. See Geolocation.

ThreatPolicy​

threat-policies · waf.extensions.cloud-apim.com/ThreatPolicy

FieldTypeDefault
enabledbooleantrue
dry_runbooleantrue — records, enforces nothing
tiersThreatTier[]log at 40, tarpit at 70, ban at 90
exemptionsstring[][] — addresses and CIDRs that bypass the fabric
ban_identityauto | ip | apikeyauto
waf_block_weightnumber50
challenge_providerstring | nullnull — required by a challenge tier
slow_refusal_millisnumber0 — how long a refusal is held before it is sent

ThreatTier​

FieldTypeDefault
min_scorenumber—
actionlog | challenge | throttle | tarpit | deny | banlog
tarpit_millisnumber3000
ban_for_secondsnumber3600
statusnumber403
throttle_quotanumber20 — requests a throttle tier lets through per window
throttle_window_secondsnumber10

An unrecognised action degrades to log, never to deny. An action is accepted only once something implements it: one with no module behind it would be a tier that silently does nothing.

BotPolicy​

bot-policies · waf.extensions.cloud-apim.com/BotPolicy

FieldTypeDefault
enabledbooleantrue
signaturesBotSignature[]the 27 built-in ones
rulesBotRule[]allow search and monitoring, monitor ai, monitor seo at weight 10
verify_known_botsbooleantrue — forward-confirmed reverse DNS
verified_bypassbooleantrue — a verified crawler is let through
impersonator_weightnumber60 — what a failed verification is worth
impersonator_actionallow | monitor | denydeny
unknown_bot_weightnumber0
deny_statusnumber403
robots_extrastring"" — appended to the generated robots.txt
llms_txtstring""

BotRule​

FieldTypeDefault
targetcategory:<name> | name:<bot> | **
actionallow | monitor | denymonitor
weightnumber0

Categories are search, ai, seo and monitoring. There is no challenge action here on purpose — give the rule a weight that reaches a challenge tier in the threat policy, so the decision stays in one place. See verified crawlers.

ChallengeProvider​

challenge-providers · waf.extensions.cloud-apim.com/ChallengeProvider

FieldTypeDefault
enabledbooleantrue
kindpow | vendorpow
difficulty_floornumber18 — leading zero bits at the low end
difficulty_ceilingnumber24 — reached by a high-scoring caller
challenge_ttl_secondsnumber300
clearance_ttl_secondsnumber1800
cookie_namestringcloud-apim-clearance
secretstring"" — falls back to the extension secret
bind_ip / bind_uabooleantrue — clearance is not transferable
title / messagestringinterstitial copy

kind: vendor adds preset_ref, widget_script_url, widget_html, response_field, verify_url, site_key and secret_key. The Challenge presets page fills those in for Friendly Captcha, captcha.eu, Turnstile and hCaptcha. See challenges.

HoneypotPolicy​

honeypot-policies · waf.extensions.cloud-apim.com/HoneypotPolicy

FieldTypeDefault
enabledbooleantrue
pathsstring[]/.env, /.git/config, …
weightnumber100
actionmonitor | deny | bandeny
ban_for_secondsnumber86400
statusnumber404 — a decoy should look like it does not exist
canariesCanaryToken[][]

CanaryToken​

FieldTypeDefault
valuestring—
descriptionstring""
whereany | header | path | queryany

This one is evaluated before routing, from the global configuration — it has no route plugin. See honeypots.

AlertRule​

alert-rules · waf.extensions.cloud-apim.com/AlertRule

FieldTypeDefault
enabledbooleantrue
triggerincident | ban | burstincident
min_scorenumber70 — incident: the highest score it reached
min_countnumber1 — incident: the decisions it folds
enforced_onlybooleantrue — incident and burst: count only what was enforced
categoriesstring[][] — every category
routesstring[][] — every route, by id or name
burst_thresholdnumber100
burst_window_secondsnumber60
cooldown_secondsnumber900 — one alert per key within it, cluster-wide
channelAlertChannelSlack

AlertChannel​

FieldTypeDefault
kindslack | teams | pagerduty | webhook | eventslack
urlstring"" — PagerDuty's Events API v2 when empty
routing_keystring"" — PagerDuty only
headersobject{} — webhook only
timeout_millisnumber10000

See alerting.

MalwareScanner​

malware-scanners · waf.extensions.cloud-apim.com/MalwareScanner

FieldTypeDefault
enabledbooleantrue
kindclamd | icapclamd
hoststring127.0.0.1
portnumber3310 for clamd, 1344 for ICAP
servicestringavscan — ICAP only
icap_moderespmod | reqmodrespmod
timeout_millisnumber30000
max_file_sizenumber26214400 — keep it under what the scanner accepts

See malware scanning.

ApiContract​

api-contracts · waf.extensions.cloud-apim.com/ApiContract

FieldTypeDefault
enabledbooleantrue
specstringan example — the OpenAPI 3.0 or 3.1 document, JSON or YAML
base_pathstring"" — the path of the contract's first server

See API contracts. A route names its own under the metadata key cloud-apim-api-contract.

RuleFeed​

rule-feeds · waf.extensions.cloud-apim.com/RuleFeed

FieldTypeDefault
enabledbooleantrue
urlstring"" — https://, or file:
headersobject{}
trusted_keysstring[][] — Ed25519 public keys, PEM or base64
allow_unsignedbooleanfalse
packsstring[][] — every pack of the feed
refresh_interval_secondsnumber3600, at least 60
timeout_millisnumber30000
promotion_delay_secondsnumber0

Each pack of an installed version is a WafRuleset with the id rule-feed_<feed>_<pack>, tagged managed. See rule feeds.

Secrets

headers on a feed, api_key / push_password on a bouncer, and an alert rule's channel url, routing_key and headers, all go through Otoroshi's secret filling. Use vault references rather than literal values.