Files
dev_blog/caddy/coraza.conf
T

34 lines
1.3 KiB
Plaintext

# ---------------------------------------------------------------------------
# Local Coraza overrides.
#
# The recommended base config and the OWASP CRS are loaded from the Caddyfile
# via the `load_owasp_crs` directive (which exposes them under the
# @coraza.conf-recommended, @crs-setup.conf.example, and @owasp_crs/* aliases).
#
# Add per-site exceptions / tuning below.
# ---------------------------------------------------------------------------
# Engine in blocking mode.
SecRuleEngine On
# Reasonable request-body limits for a static blog.
SecRequestBodyLimit 13107200
SecRequestBodyNoFilesLimit 131072
SecRequestBodyLimitAction Reject
# Drop very noisy false-positives on static asset paths.
SecRule REQUEST_URI "@beginsWith /_astro/" \
"id:1000,phase:1,pass,nolog,ctl:ruleEngine=Off"
SecRule REQUEST_URI "@beginsWith /fonts/" \
"id:1001,phase:1,pass,nolog,ctl:ruleEngine=Off"
# ---------------------------------------------------------------------------
# Audit log — every blocked request gets an entry in serial format that
# fail2ban tails on the host (mounted at /var/log/caddy/coraza-audit.log).
# ---------------------------------------------------------------------------
SecAuditEngine RelevantOnly
SecAuditLogRelevantStatus "^(?:5|4(?!04))"
SecAuditLogParts ABIJDEFHZ
SecAuditLogType Serial
SecAuditLog /var/log/caddy/coraza-audit.log