You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Serverless框架中如何为生产和非生产环境配置不同规则的WAF?

Serverless框架分环境配置CloudFront WAF的最佳实现

核心逻辑

通过Serverless框架原生的环境变量+CloudFormation条件语法,实现资源的按需创建和关联,无需维护多套配置文件。

具体配置步骤

1. 定义分环境的WAF配置参数

在serverless.yml的custom字段中按环境声明WAF开关、白名单IP段等参数:

custom:
  # 读取当前部署环境,默认取provider中配置的stage
  currentStage: ${opt:stage, self:provider.stage}
  # 分环境WAF配置
  wafSettings:
    dev:
      enableWaf: true
      vpnIpWhitelist:
        - "123.123.123.123/32" # 替换为企业VPN出口公网IP段
        - "45.45.45.0/24"
    prod:
      enableWaf: false

2. 声明WAF资源创建条件

在resources块中新增条件判断,仅在WAF开启的环境下创建相关资源:

provider:
  name: aws
  stage: dev
  # CloudFront关联的WAF必须部署在us-east-1区域,固定该区域即可
  region: us-east-1

resources:
  Conditions:
    # 只有当前环境WAF开关为true时,相关WAF资源才会被创建
    IsWafEnabled: ${self:custom.wafSettings.${self:custom.currentStage}.enableWaf}

  Resources:
    # 1. 声明VPN白名单IP集
    VpnWhitelistIpSet:
      Type: AWS::WAFv2::IPSet
      Condition: IsWafEnabled
      Properties:
        Name: ${self:custom.currentStage}-vpn-whitelist-ipset
        Scope: CLOUDFRONT
        IPAddressVersion: IPV4
        Addresses: ${self:custom.wafSettings.${self:custom.currentStage}.vpnIpWhitelist}

    # 2. 声明非生产环境WebACL规则:默认拦截所有请求,仅放行VPN白名单IP
    NonProdWebAcl:
      Type: AWS::WAFv2::WebACL
      Condition: IsWafEnabled
      DependsOn: VpnWhitelistIpSet
      Properties:
        Name: ${self:custom.currentStage}-cloudfront-webacl
        Scope: CLOUDFRONT
        DefaultAction:
          Block: {}
        Rules:
          - Name: allow-vpn-access
            Priority: 1
            Action:
              Allow: {}
            Statement:
              IPSetReferenceStatement:
                Arn: !GetAtt VpnWhitelistIpSet.Arn
            VisibilityConfig:
              SampledRequestsEnabled: true
              CloudWatchMetricsEnabled: true
              MetricName: ${self:custom.currentStage}-allow-vpn
        VisibilityConfig:
          SampledRequestsEnabled: true
          CloudWatchMetricsEnabled: true
          MetricName: ${self:custom.currentStage}-cloudfront-webacl

3. CloudFront分发条件关联WAF

在你已有的CloudFront资源配置中,新增WebACLId的条件赋值:

StaticSiteCloudFront:
  Type: AWS::CloudFront::Distribution
  Properties:
    DistributionConfig:
      Enabled: true
      Origins:
        - DomainName: !GetAtt StaticSiteS3Bucket.DomainName
          Id: S3StaticOrigin
          S3OriginConfig:
            OriginAccessIdentity: !Sub origin-access-identity/cloudfront/${CloudFrontOAI}
      DefaultCacheBehavior:
        TargetOriginId: S3StaticOrigin
        ViewerProtocolPolicy: redirect-to-https
        # 其余缓存、响应头配置省略
      # 条件关联WAF:非生产环境关联WebACL,生产环境不配置
      WebACLId: !If
        - IsWafEnabled
        - !GetAtt NonProdWebAcl.Arn
        - !Ref AWS::NoValue

部署验证

  • 部署非生产环境:执行 sls deploy --stage dev,框架会自动创建WAF资源并关联到CloudFront
  • 部署生产环境:执行 sls deploy --stage prod,不会创建任何WAF相关资源,CloudFront也不会关联WAF

注意事项

  • 如果生产环境也需要配置基础防护规则(比如OWASP Top10拦截),仅需修改prod环境的enableWaf为true,并新增对应规则配置即可,无需修改核心逻辑
  • 企业VPN出口IP变更时,仅需更新vpnIpWhitelist参数重新部署即可
  • 不要修改WAF的部署区域,CloudFront关联的WAFv2资源要求必须部署在us-east-1区域

内容的提问来源于stack exchange,提问作者systemdebt

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.05 10:06:04