You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Terraform配置WAF豁免规则时同时使用两种Statement报错求助

如何在Terraform中为特定WAF端点排除SQLi规则拦截

需求可行性说明

你的需求完全可行——AWS WAF支持针对特定路径跳过指定Managed Rule的检测,错误的根源是每个WAF Rule的statement字段只能包含一个顶层语句,不能同时放置managed_rule_group_statement和byte_match_statement,这就是触发WAFInvalidParameterException的原因。

两种修正方案

方案1:使用Managed Rule Group的Scope-down Statement

通过scope_down_statement限定Managed Rule Group仅对非例外路径生效,直接在SQLi规则组内部过滤掉不需要检测的请求:

resource "aws_wafv2_web_acl" "example" {
  name        = "api-web-acl"
  description = "Web ACL with SQLi exclusion for /api/events and /documents/messages"
  scope       = "REGIONAL" # 根据你的资源区域调整,比如"CLOUDFRONT"
  default_action {
    allow {}
  }

  rule {
    name     = "SQLi-Protection-Exclude-Specific-Paths"
    priority = 1
    action {
      block {}
    }
    statement {
      managed_rule_group_statement {
        name        = "AWSManagedRulesSQLiRuleSet"
        vendor_name = "AWS"
        version     = "VERSION_1"

        # 仅对不匹配例外路径的请求应用SQLi规则
        scope_down_statement {
          not_statement {
            statement {
              or_statement {
                statement {
                  byte_match_statement {
                    field_to_match {
                      uri_path {}
                    }
                    positional_constraint = "STARTS_WITH"
                    search_string         = "/api/events"
                    text_transformation {
                      priority = 0
                      type     = "NONE"
                    }
                  }
                }
                statement {
                  byte_match_statement {
                    field_to_match {
                      uri_path {}
                    }
                    positional_constraint = "STARTS_WITH"
                    search_string         = "/documents/messages"
                    text_transformation {
                      priority = 0
                      type     = "NONE"
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name                = "SQLi-Protection-Exclude-Specific-Paths"
      sampled_requests_enabled   = true
    }
  }
}

方案2:通过规则优先级拆分逻辑

先定义一条高优先级规则,匹配例外路径并直接放行(或标记为跳过),再在低优先级规则中应用SQLi检测:

resource "aws_wafv2_web_acl" "example" {
  name        = "api-web-acl"
  description = "Web ACL with path-based exclusion before SQLi rules"
  scope       = "REGIONAL"
  default_action {
    allow {}
  }

  # 优先级最高:匹配例外路径,直接Allow(若需保留后续规则检测可改用count{})
  rule {
    name     = "Exclude-SQLi-For-Specific-Endpoints"
    priority = 0
    action {
      allow {}
    }
    statement {
      or_statement {
        statement {
          byte_match_statement {
            field_to_match {
              uri_path {}
            }
            positional_constraint = "STARTS_WITH"
            search_string         = "/api/events"
            text_transformation {
              priority = 0
              type     = "NONE"
            }
          }
        }
        statement {
          byte_match_statement {
            field_to_match {
              uri_path {}
            }
            positional_constraint = "STARTS_WITH"
            search_string         = "/documents/messages"
            text_transformation {
              priority = 0
              type     = "NONE"
            }
          }
        }
      }
    }
    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name                = "Exclude-SQLi-For-Specific-Endpoints"
      sampled_requests_enabled   = true
    }
  }

  # 优先级次之:对非例外路径应用SQLi规则
  rule {
    name     = "AWS-SQLi-Protection"
    priority = 1
    action {
      block {}
    }
    statement {
      managed_rule_group_statement {
        name        = "AWSManagedRulesSQLiRuleSet"
        vendor_name = "AWS"
        version     = "VERSION_1"
      }
    }
    visibility_config {
      cloudwatch_metrics_enabled = true
      metric_name                = "AWS-SQLi-Protection"
      sampled_requests_enabled   = true
    }
  }
}

方案选择建议

  • 方案1更高效:SQLi规则组仅处理需要检测的请求,减少WAF计算开销
  • 方案2更灵活:例外路径可继续触发后续Web ACL规则,适合需要对这些路径做其他检测的场景

内容的提问来源于stack exchange,提问作者onev

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 04:40:36