# --------------------------------------------------------------------------- # Local Coraza overrides. # # The recommended base config and the OWASP CRS are loaded from the Caddyfile # via the `load_owasp_crs` directive (which exposes them under the # @coraza.conf-recommended, @crs-setup.conf.example, and @owasp_crs/* aliases). # # Add per-site exceptions / tuning below. # --------------------------------------------------------------------------- # Engine in blocking mode. SecRuleEngine On # Reasonable request-body limits for a static blog. SecRequestBodyLimit 13107200 SecRequestBodyNoFilesLimit 131072 SecRequestBodyLimitAction Reject # Drop very noisy false-positives on static asset paths. SecRule REQUEST_URI "@beginsWith /_astro/" \ "id:1000,phase:1,pass,nolog,ctl:ruleEngine=Off" SecRule REQUEST_URI "@beginsWith /fonts/" \ "id:1001,phase:1,pass,nolog,ctl:ruleEngine=Off" # --------------------------------------------------------------------------- # Audit log — every blocked request gets an entry in serial format that # fail2ban tails on the host (mounted at /var/log/caddy/coraza-audit.log). # --------------------------------------------------------------------------- SecAuditEngine RelevantOnly SecAuditLogRelevantStatus "^(?:5|4(?!04))" SecAuditLogParts ABIJDEFHZ SecAuditLogType Serial SecAuditLog /var/log/caddy/coraza-audit.log