{"id":13449952,"url":"https://github.com/globaldatanet/aws-firewall-factory","last_synced_at":"2025-03-23T16:30:59.943Z","repository":{"id":38308369,"uuid":"424974259","full_name":"globaldatanet/aws-firewall-factory","owner":"globaldatanet","description":"Easily improve the security of your web applications with aws firewall factory. Protect your valuable assets with seamless WAF deployment, updates, and staging, all efficiently managed centrally with Firewall Manager.","archived":false,"fork":false,"pushed_at":"2024-05-06T10:17:13.000Z","size":28308,"stargazers_count":221,"open_issues_count":13,"forks_count":21,"subscribers_count":5,"default_branch":"master","last_synced_at":"2024-05-10T18:57:43.449Z","etag":null,"topics":["amazon-web-services","aws","cdk","devsecops","firewall","governance","hacktoberfest","owasp","owasp-top-10","security","typescript","waf","wafv2"],"latest_commit_sha":null,"homepage":"https://docs.aws-firewall-factory.com/","language":"TypeScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/globaldatanet.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"Code_of_Conduct.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-11-05T14:20:54.000Z","updated_at":"2024-05-27T13:32:39.659Z","dependencies_parsed_at":"2024-04-15T07:41:50.554Z","dependency_job_id":"3d55db62-f7b9-475b-aa30-0d0b50f7c715","html_url":"https://github.com/globaldatanet/aws-firewall-factory","commit_stats":null,"previous_names":[],"tags_count":51,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/globaldatanet%2Faws-firewall-factory","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/globaldatanet%2Faws-firewall-factory/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/globaldatanet%2Faws-firewall-factory/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/globaldatanet%2Faws-firewall-factory/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/globaldatanet","download_url":"https://codeload.github.com/globaldatanet/aws-firewall-factory/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245130693,"owners_count":20565694,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["amazon-web-services","aws","cdk","devsecops","firewall","governance","hacktoberfest","owasp","owasp-top-10","security","typescript","waf","wafv2"],"created_at":"2024-07-31T07:00:23.421Z","updated_at":"2025-03-23T16:30:54.906Z","avatar_url":"https://github.com/globaldatanet.png","language":"TypeScript","funding_links":[],"categories":["Tools of Trade","AWS","Projects","Infrastructure","Security Tools","Construct Libraries","aws","Awesome Tools"],"sub_categories":["Firewall Management","Interfaces","Security","Management:"],"readme":"\n[![Mentioned in Awesome CDK](https://awesome.re/mentioned-badge.svg)](https://github.com/kolomied/awesome-cdk)\n[![License: Apache2](https://img.shields.io/badge/license-Apache%202-lightgrey.svg)](http://www.apache.org/licenses/) [![cdk](https://img.shields.io/badge/aws_cdk-v2-orange.svg)](https://docs.aws.amazon.com/cdk/v2/guide/home.html)\n[![latest](https://img.shields.io/badge/latest-release-yellow.svg)](https://github.com/globaldatanet/aws-firewall-factory/releases)\n[![gdn](https://img.shields.io/badge/opensource-@globaldatanet-%2300ecbd)](https://globaldatanet.com/opensource) [![dakn](https://img.shields.io/badge/by-dakn-%23ae0009.svg)](https://github.com/daknhh)\n[![TypeScript](https://badges.frapsoft.com/typescript/love/typescript.png?v=101)](https://github.com/ellerbrock/typescript-badges/)\n[![Tweet](https://img.shields.io/twitter/url/http/shields.io.svg?style=social)](https://twitter.com/intent/tweet?text=AWS%20FIREWALL%20FACTORY%20-%20Deploy%2C%20update%2C%20and%20stage%20your%20WAFs%20while%20managing%20them%20centrally%20via%20FMS\u0026url=https://github.com/globaldatanet/aws-firewall-factory\u0026hashtags=aws,security,waf)\n[![roadmap](https://img.shields.io/badge/public-roadmap-yellow.svg)](https://github.com/orgs/globaldatanet/projects/1)\n\n\n**[🚧 Feature request](https://github.com/globaldatanet/aws-firewall-factory/issues/new?assignees=\u0026labels=feature-request%2C+enhancement\u0026template=feature_request.md\u0026title=)** | **[🐛 Bug Report](https://github.com/globaldatanet/aws-firewall-factory/issues/new?assignees=\u0026labels=bug%2C+triage\u0026template=bug_report.md\u0026title=)**\n\n\u003cimg src=\"https://socialify.git.ci/globaldatanet/aws-firewall-factory/image?font=Bitter\u0026forks=1\u0026logo=https%3A%2F%2Fgithub.com%2Fglobaldatanet%2Faws-firewall-factory%2Fraw%2F4.1.3%2Fstatic%2Ficon%2Ffirewallfactory.svg\u0026name=1\u0026pattern=Solid\u0026stargazers=1\u0026theme=Dark\" alt=\"aws-firewall-factory\" width=\"640\" height=\"320\" /\u003e\n\n## 𒋰 Table of contents\n\n- [𒋰 Table of contents](#𒋰-table-of-contents)\n- [🔭 Overview](#-overview)\n- [🎬 Media](#-media)\n    - [🔗 Useful Links](#-useful-links)\n- [🗺️ Architecture](#️-architecture)\n- [🧪 Tests](#-tests)\n- [🦸🏼‍♀️ Contributors](#️-contributors)\n  - [👩‍💻 Contribute](#-contribute)\n  - [👏 Supporters](#-supporters)\n\n|                     Releases                      | Author |\n|---------------------------------------------------|--------|\n| [Changelog](CHANGELOG.md) - [Features](Features.md) - [🛡️ Deployment](Deployment.md) | David Krohn \u003c/br\u003e [Linkedin](https://www.linkedin.com/in/daknhh/) - [Blog](https://globaldatanet.com/our-team/david-krohn)|\n\n\u003c/br\u003e\n\n## 🔭 Overview\n\n\u003cimg align=\"left\" src=\"./static/icon/firewallfactory.svg\" width=\"150\"\u003e\n\nAWS Web Application Firewalls (WAFs) protect web applications and APIs from typical attacks from the Internet that can compromise security and availability, and put undue strain on servers and resources. The AWS WAF provides prebuilt security rules that help control bot traffic and block attack patterns. You can also create your own rules based on your own requirements. In simple scenarios and for smaller applications, this is very easy to implement on an individual basis. However, in larger environments with tens or even hundreds of applications, it is advisable to aim for central governance and automation. This simple solution helps you deploy, update and stage your Web Application Firewalls while managing them centrally via AWS Firewall Manager.\n\n![Example Deployment](./static/example-deployment.gif \"Example Deployment\")\n\n## 🎬 Media\n\nIf you want to learn more about the AWS Firewall Factory feel free to look at the following media resources.\n\n- [📺 Webinar: Web Application Firewalls at Scale - Language: 🇩🇪](https://globaldatanet.com/webinars/aws-security-with-security-in-the-cloud)\n- [📺 Webinar: Managing AWS Web Application Firewalls at Scale - Language: 🇺🇸](https://globaldatanet.com/webinars/managing-aws-web-application-firewalls-at-scale)\n- [📺 Webinar: Secure Serverless Applications against OWASP TOP 10 in 5 mins - Language: 🇺🇸](https://serverless-summit.io/)\n- [📊 Slides: Managing AWS Web Application Firewalls at Scale - Language: 🇺🇸](https://docs.google.com/presentation/d/1jE_DmNk0cCc1XM8eBYPM2za0pzGyg9Lv/edit?usp=sharing\u0026ouid=115444461121738087344\u0026rtpof=true\u0026sd=true)\n- Secure Serverless Applications against OWASP TOP 10 in 5 Minutes - Language: 🇺🇸\n  - [📊 Slides](https://docs.google.com/file/d/1YJCfTt8ILa2R9n23fHDFLpfLhTwhB4ea/edit?filetype=mspresentation) - [📺 Video](https://www.youtube.com/watch?v=jrYpr0DLKfo)\n\n#### 🔗 Useful Links\n\n- [🐦🤖 Twitter Bot to get Notified for Managed Rules Updates](https://twitter.com/AWSMgMtRulesBot)\n- [🏫 AWS WAF Workshop](https://catalog.us-east-1.prod.workshops.aws/workshops/c2f03000-cf61-42a6-8e62-9eaf04907417/en-US/02-custom-rules)\n## 🗺️ Architecture\n\n![Architecture](./static/AWSFIREWALLMANAGER.png \"Architecture\")\n\n## 🧪 Tests\n|  Test | Status  |\n|---|---|\n|  CodeQL | ![CodeQL](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/github-code-scanning/codeql/badge.svg?branch=master)  |\n|  Linting | ![linting](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/linting.yml/badge.svg?branch=master)  |\n|  WAF Deployment - Only Managed Rule Groups  | ![onlyManagedRuleGroups](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/waf_test_onlymanagedrulegroups.yml/badge.svg?branch=master)  |\n|  WAF Deployment - Only Managed Rule Groups with Excludes | ![rateBasedwithScopeDown](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/waf_test_onlymanagedrulegroupsWithExcludes.yml/badge.svg?branch=master)  |\n|  WAF Deployment - IpSets | ![IpSets](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/waf_test_ipSets.yml/badge.svg?branch=master)   |\n|  WAF Deployment - RegexPatternSets | ![regexPatternSets](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/waf_test_regexPatternSets.yml/badge.svg?branch=master)  |\n|  WAF Deployment - RateBasedwithScopeDown | ![rateBasedwithScopeDown](https://github.com/globaldatanet/aws-firewall-factory/actions/workflows/waf_test_rateBasedwithScopeDown.yml/badge.svg?branch=master)  |\n\n\n## 🦸🏼‍♀️ Contributors\n\n\u003ca href=\"https://github.com/globaldatanet/aws-firewall-factory/graphs/contributors\"\u003e\n  \u003cimg src=\"https://contrib.rocks/image?repo=globaldatanet/aws-firewall-factory\" /\u003e\n\u003c/a\u003e\n\n\u003c/br\u003e\nAny form of contribution is welcome. The above contributors have been officially released by globaldatanet.\n\u003c/br\u003e\n\u003c/br\u003e\n\n\u003c/div\u003e\n\n\u003c/details\u003e\n\n### 👩‍💻 Contribute\n\nWant to contribute to **AWS FIREWALL FACTORY**? Check out the [Contribution docs](./CONTRIBUTING.md)\n\u003c/br\u003e\n\n### 👏 Supporters\n\n[![Stargazers repo roster for @globaldatanet/aws-firewall-factory](http://bytecrank.com/nastyox/reporoster/php/stargazersSVG.php?user=globaldatanet\u0026repo=aws-firewall-factory)](https://github.com/globaldatanet/aws-firewall-factory/stargazers)\n\n\u003c/br\u003e\n\n\u003cp align=\"center\"\u003e\u003ca href=\"https://github.com/globaldatanet/aws-firewall-factory\"\u003e\u003cimg src=\"./static/barsSmallTransparentBackground.gif\" width=\"100%\"/\u003e\u003c/a\u003e\u003c/p\u003e\n\n[^1]: Optional Fields. \n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fglobaldatanet%2Faws-firewall-factory","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fglobaldatanet%2Faws-firewall-factory","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fglobaldatanet%2Faws-firewall-factory/lists"}