Bind a rule set in azion.config.js
Declare the WAF rule set and the firewall rule that applies it in azion.config.js, so the Azion CLI creates both from the repository.
You can declare a WAF rule set and the firewall rule that applies it in azion.config.js, and let the Azion CLI create both from the file. Both then live in the repository, under review alongside the application they protect.
Prerequisites
You need the Azion CLI installed and a configured personal token.
Declare the rule set and the rule
In azion.config.js, declare the firewall with waf: true, the rule that carries the setWafRuleset behavior, and the rule set under waf:
The Azion CLI reads the file and creates what it declares: the firewall with WAF turned on, the rule set, and the rule that applies it.
waf: true on the firewall turns WAF on, and it stays off until you turn it on. A family you leave out of thresholds is not configured, so list every family you want scored. setWafRuleset takes exactly two keys, wafMode and wafId. wafMode takes learning or blocking in this file: the same mode reads Logging in Azion Console and logging in an API payload. For what each mode does, refer to Scoring and modes.