You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Terraform修改AWS WAF配置,允许requestBodySize达32KB

AWS WAF 请求体大小限制调整问题解决方法

问题背景

通过Terraform配置AWS WAF并使用AWS-AWSManagedRulesCommonRuleSet托管规则集时,请求体超过16KB就会被拦截。尝试添加自定义规则允许最大32KB请求体,但未生效。CloudWatch日志显示:

requestBodySize   301984
requestBodySizeInspectedByWAF  16384

原因分析

  1. AWS WAF默认仅检查请求体的前16KB内容,即使自定义规则设置了32KB限制,WAF实际未获取完整请求体,导致规则判断无效。
  2. AWS-AWSManagedRulesCommonRuleSet托管规则集内置SizeRestrictions_BODY规则,默认拦截超过16KB的请求体,这是拦截的直接原因。

解决方案

需要同时调整WAF的请求体检查范围,并覆盖托管规则集中的默认大小限制规则,具体Terraform配置修改如下:

修改后的完整Web ACL配置

resource "aws_wafv2_web_acl" "your_web_acl" {
  name        = "your-web-acl-name"
  description = "Web ACL allowing up to 32KB request body"
  scope       = "REGIONAL" # 根据实际场景选择REGIONAL或CLOUDFRONT

  default_action {
    allow {}
  }

  # 核心配置:设置WAF检查请求体的最大大小为32KB
  request_body_inspection {
    enabled = true
    size_limit_in_bytes = 32768 # 32KB对应的字节数
  }

  # 自定义大小限制规则(可选,可配合托管规则override使用)
  rule {
    name     = "CustomSizeConstraintRule"
    priority = 0
    action {
      allow {}
    }
    statement {
      size_constraint_statement {
        comparison_operator = "LE"
        size                = 32768
        field_to_match {
          body {}
        }
        text_transformation {
          priority = 0
          type     = "NONE"
        }
      }
    }
    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name                = "CustomSizeConstraintRule"
      sampled_requests_enabled   = true
    }
  }

  # 托管规则集,并覆盖内置的大小限制规则
  rule {
    name     = "AWS-AWSManagedRulesCommonRuleSet"
    priority = 2
    statement {
      managed_rule_group_statement {
        name        = "AWS-AWSManagedRulesCommonRuleSet"
        vendor_name = "AWS"
        # 覆盖托管规则集中的SizeRestrictions_BODY规则,允许32KB请求体
        rule_action_override {
          name = "SizeRestrictions_BODY"
          action_to_use {
            allow {}
          }
        }
      }
    }
    override_action {
      none {}
    }
    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name                = "AWS-AWSManagedRulesCommonRuleSet"
      sampled_requests_enabled   = true
    }
  }

  visibility_config {
    cloudwatch_metrics_enabled = true
    metric_name                = "your-web-acl-metric"
    sampled_requests_enabled   = true
  }
}

关键配置说明

  • request_body_inspection:指定WAF检查请求体的最大字节数为32768,确保WAF能获取完整的请求体内容,这是自定义规则和托管规则生效的前提。
  • rule_action_override:针对托管规则集中的SizeRestrictions_BODY规则,将其动作改为allow,覆盖默认的16KB限制。
  • 规则优先级:自定义规则优先级设为0,确保先执行,但核心生效逻辑仍依赖请求体检查范围和托管规则的覆盖。

验证

部署修改后的Terraform配置后,发送超过16KB但小于等于32KB的请求,检查CloudWatch日志中requestBodySizeInspectedByWAF是否等于requestBodySize,同时确认请求未被拦截。

内容的提问来源于stack exchange,提问作者Madhawa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 13:09:53