coraza: add second Include for runtime-managed local-overrides.conf
This commit is contained in:
@@ -39,6 +39,8 @@ LABEL org.opencontainers.image.title="coraza-spoa-whp" \
|
|||||||
COPY --from=build /out/coraza-spoa /coraza-spoa
|
COPY --from=build /out/coraza-spoa /coraza-spoa
|
||||||
COPY config.yaml /etc/coraza-spoa/config.yaml
|
COPY config.yaml /etc/coraza-spoa/config.yaml
|
||||||
COPY overrides.conf /etc/coraza/overrides.conf
|
COPY overrides.conf /etc/coraza/overrides.conf
|
||||||
|
COPY local-overrides.conf /etc/coraza/local-overrides.conf
|
||||||
|
COPY host-exceptions/ /etc/coraza/host-exceptions/
|
||||||
|
|
||||||
# Audit log directory — bind-mount /var/log/coraza:/var/log/coraza from host
|
# Audit log directory — bind-mount /var/log/coraza:/var/log/coraza from host
|
||||||
# so logs persist across container restarts and AI Monitor can tail them.
|
# so logs persist across container restarts and AI Monitor can tail them.
|
||||||
|
|||||||
@@ -34,6 +34,9 @@ applications:
|
|||||||
# to see exactly what blocks vs what's detect-only.
|
# to see exactly what blocks vs what's detect-only.
|
||||||
Include /etc/coraza/overrides.conf
|
Include /etc/coraza/overrides.conf
|
||||||
|
|
||||||
|
# Runtime-managed overrides written by WHP UI. Empty by default.
|
||||||
|
Include /etc/coraza/local-overrides.conf
|
||||||
|
|
||||||
# Global mode: log all alerts, block only what overrides.conf
|
# Global mode: log all alerts, block only what overrides.conf
|
||||||
# explicitly promotes via ctl:ruleEngine=On.
|
# explicitly promotes via ctl:ruleEngine=On.
|
||||||
SecRuleEngine DetectionOnly
|
SecRuleEngine DetectionOnly
|
||||||
|
|||||||
0
coraza-spoa/host-exceptions/.gitkeep
Normal file
0
coraza-spoa/host-exceptions/.gitkeep
Normal file
3
coraza-spoa/local-overrides.conf
Normal file
3
coraza-spoa/local-overrides.conf
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
# AUTOGENERATED by WHP — do not hand-edit.
|
||||||
|
# Source of truth: whp.security_db coraza_rule_overrides table.
|
||||||
|
# Empty file = no runtime overrides; baked-in overrides.conf governs.
|
||||||
Reference in New Issue
Block a user