# Edge web application firewall appliance

Source: https://docs.quake.ai/resources/iac-templates/edge-waf
Markdown: https://docs.quake.ai/resources/iac-templates/edge-waf.md

---

# Edge web application firewall appliance

This pattern composes Compute, Network, and Block Storage into a self-hosted L7 web application firewall on infrastructure you control.

## What this template does

Provisions a single instance running [SafeLine](https://github.com/chaitin/SafeLine), an open-source WAF with a management dashboard, that inspects HTTP traffic on a floating IP and forwards clean requests to a private backend:

- Compute instance that runs SafeLine in Docker, sized for the detection engine (2 vCPU and 2 GiB RAM by default)
- Private network, subnet, router, port, and security group; a floating IP on the WAF only
- A block volume mounted at `/data`, so rules, logs, and Postgres state live on a volume you can grow rather than on the boot disk
- cloud-init installs Docker, downloads the official SafeLine compose bundle, generates a Postgres password on first boot, and starts SafeLine

The backend stays on the private subnet with no floating IP of its own. You configure the protected site in the SafeLine dashboard to forward to `upstream_host` and `upstream_port`, then lock the backend security group to accept traffic only from the WAF security group.

No credential ships with this template. Run `docker exec safeline-mgt resetadmin` on the instance after first boot to retrieve the one-time admin password.

## Honest scope

This WAF runs in one region on a VM you operate. It is an L7 application firewall: it inspects HTTP semantics for injection, cross-site scripting, and related attack patterns. It is not a CDN and it does not absorb L3/L4 volumetric DDoS traffic. For geographic distribution and edge absorption, [front the origin with a third-party CDN](/docs/network/how-to/front-with-cdn) or use a [CDN-layer WAF](/docs/network/how-to/front-with-waf).

## Alternate engines

This template leads with SafeLine (GPL-3.0, semantic-analysis engine, dashboard, Docker install). [BunkerWeb](https://www.bunkerweb.io) fits when you want Nginx with OWASP CRS and security-by-default reverse-proxy rules. [Coraza](https://coraza.io) fits when you embed WAF logic inside Caddy or Envoy on the [edge reverse proxy](/resources/iac-templates/edge-reverse-proxy) template instead of running a separate appliance.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (SafeLine scales with CPU; throughput is bounded per core) | `s1a.small` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `edge-waf` |
| `safeline_version` | SafeLine container image tag | `latest` |
| `mgt_port` | Management dashboard port (reach via SSH tunnel) | `9443` |
| `domain` | Public hostname for the protected site (used in `waf_url` output) | `""` |
| `upstream_host` | Private IP of the backend instance | `10.42.0.10` |
| `upstream_port` | TCP port the backend listens on | `8080` |
| `volume_size` | Block volume size in GiB, mounted at `/data` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.42.0.0/24` |

## Ports and access

| Port | Purpose |
| --- | --- |
| 22 | Host SSH for administration |
| 80 | HTTP entry through the WAF after you configure the protected site |
| 443 | HTTPS entry when TLS is enabled on the protected site |
| 9443 | SafeLine management dashboard (not opened in the security group; use an SSH tunnel) |

## When to use this pattern

Run your own L7 WAF on a VM you operate so attack traffic is filtered before it reaches a private app backend. This security-focused template in the edge and gateway family implements the self-managed WAF path from [front with a WAF](/docs/network/how-to/front-with-waf).

For the TLS-only front door without a WAF engine, see the [edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy). For DNS join points, see [point a domain to Quake AI](/docs/network/how-to/point-domain-to-quake-ai).

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "edge-waf", required: true },
  ]}
/>

## Template source

This is a [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked).

<TemplateSource slug="edge-waf" />

<TemplateResourceMap template="edge-waf" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy the edge WAF template](/resources/deployments/deploy-edge-waf-template)
- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy)
- [Front with a WAF](/docs/network/how-to/front-with-waf)
- [Front with a CDN](/docs/network/how-to/front-with-cdn)
- [API gateway template](/resources/iac-templates/api-gateway)
