Skip to content

feat: convert ngwaf gold-standard-starter to fastly terraform provider - #33

Open
saschanowak wants to merge 1 commit into
fastly:mainfrom
saschanowak:terraform-migration-for-gold-standard-starter
Open

saschanowak wants to merge 1 commit into
fastly:mainfrom
saschanowak:terraform-migration-for-gold-standard-starter

Conversation

@saschanowak

Copy link
Copy Markdown

Summary

Migrates the gold-standard-starter example from the legacy signalsciences/sigsci
provider to the official fastly/fastly Terraform provider (>= 9.3.0), aligning it
with Fastly's unified account model. Corp-scoped resources become account-scoped,
the NGWAF "site" becomes a "workspace," and authentication consolidates onto a single
Fastly API token.

Motivation

The sigsci provider predates the unified Fastly account model and is being superseded
by first-class NGWAF resources in the fastly/fastly provider. Moving the starter onto
the supported provider keeps the demo current, lets it share one credential and one
control plane with the rest of Fastly, and removes the separate Signal Sciences corp/site/email
auth surface.

Changes

Provider & auth

  • providers.tf: swap signalsciences/sigsci (>= 3.3.0) → fastly/fastly (>= 9.3.0).
  • main.tf: provider block no longer takes corp / email / auth_token; the fastly
    provider authenticates via the FASTLY_API_KEY environment variable, reused across all
    Fastly resources.
  • variables.tf: drop NGWAF_CORP, NGWAF_SITE, NGWAF_EMAIL, and the sensitive
    NGWAF_TOKEN; add a single NGWAF_WORKSPACE variable.

Resource mapping (corp → account, site → workspace)

  • sigsci_corp_list → fastly_ngwaf_account_list
  • sigsci_corp_signal_tag → fastly_ngwaf_account_signal (now name instead of
    short_name, plus required applies_to = ["*"])
  • sigsci_corp_rule → fastly_ngwaf_account_rule
  • sigsci_site_signal_tag → fastly_ngwaf_workspace_signal (now takes workspace_id)
  • sigsci_site_rule → fastly_ngwaf_workspace_rule
  • New fastly_ngwaf_workspace resource (mode = "log") defines the tenant workspace.

Rule schema rewrites

  • Rule attributes updated: site_short_names / corp_scope / reason / expiration
    removed; description, applies_to, and request_logging = "sampled" added.
  • Nested conditions { type = "multival" } / conditions { type = "single" } blocks
    replaced with multival_condition / condition blocks; actions → action.
  • Field/operator values moved to snake_case: signalType→signal_id, inList→in_list,
    addSignal→add_signal, responseCode→response_code, requestHeader→request_header,
    valueString→value_string, doesNotEqual→does_not_equal, rateLimit→rate_limit,
    logRequest→log_request.
  • List/signal references change from .id lookups to namespaced string refs
    ("corp.${...name}" for account scope, "site.${...name}" for workspace scope).

Threshold model

  • The three separate sigsci_site_alert resources (1m/10m/60m) are replaced by the
    workspace's attack_signal_thresholds block (one_minute = 50, ten_minutes = 350,
    one_hour = 1800, immediate = false).
  • Rate-limit rule: interval corrected 1 → 60 (seconds) and signal moved inside
    the rate_limit block.

Docs & misc

  • README.md: "Corp configurations" → "Account configurations", "Site configurations" →
    "Workspace configurations", "Site Alert" → "Workspace Thresholds". Pre-reqs now point to
    a Fastly API token with service create/manage permissions and note the unified account
    model. Apply example uses TF_VAR_NGWAF_WORKSPACE.
  • Output URL updated from dashboard.signalsciences.net/corps/.../sites/... to
    manage.fastly.com/security/ngwaf/workspaces/${...id}/dashboards.
  • Fixed "Anomoly" → "Anomaly" typo and a relative README link.

Breaking changes / migration notes

  • Provider swap is breaking. Run terraform init -upgrade before applying.
  • Auth changes: export FASTLY_API_KEY instead of supplying NGWAF_CORP/SITE/
    EMAIL/TOKEN; provide the workspace name via TF_VAR_NGWAF_WORKSPACE.
  • State: this PR rewrites the .tf resources only — it does not include import
    blocks or moved/state-migration steps. Applying against state created by the sigsci
    provider will require migrating or recreating resources; a fresh terraform apply against
    an empty state is the clean path.

Testing

  • terraform init -upgrade resolves fastly/fastly >= 9.3.0
  • terraform validate passes
  • terraform apply -parallelism=1 against a test workspace creates expected
    lists, signals, account/workspace rules, and thresholds
  • Output URL links to the correct workspace dashboard

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant