Guides
How to use the kubeWAF operator — rules, CRS, challenge, providers, and ops
These guides cover the kubeWAF operator: Custom Resources, GitOps policy, and how config is pushed to Envoy Gateway, Istio, or Cilium.
Other docs roots (separate sidebars): modsecurity-proxy-wasm · pow-proxy-wasm.
Policy and rules
Writing security rules
SecLang-style rules as structured YAML and anomaly scoring.
RuleSets
Group and reuse rules across namespaces.
OWASP CRS
Enable and tune the Core Rule Set on a WAF.
Engines on the WAF CR
WAF engine
Select ModSecurity, CRS, and wasm delivery.
Proof-of-Work challenge
Enable challenge, set difficulty, manage HMAC secrets.