IaC Bazaar

Cloud Armor Security Policy (WAF)

A global Cloud Armor WAF policy with preconfigured OWASP SQLi and XSS rules enforcing by default, an optional per-client rate limit, and custom IP allow/deny rules - attachable to many backends.

This is the operations reference: version drift, dependants and neighbours. For what the module provisions, its inputs and outputs, and how to buy it, see the catalogue entry.

terraformGoogle CloudSecurity & Identityv1.1.0live-tested

Provider drift

This module's own ceiling currently holds it below a release that has already shipped. It still applies exactly as before, against the newest version it allows. What it cannot reach is anything added in the newer major.

ProviderThis module allowsNewest it acceptsNewest released
hashicorp/google>= 7.0, < 8.07.46.08.1.0

Measured 2026-09-01 against the Terraform registry. The whole catalogue is on provider freshness.

What depends on this

1 reference architecture composes this module, so a breaking change to it reaches further than the module itself. That is the blast radius to check before altering or replacing it.

Nearest alternatives

Same cloud, same category. These are what you would weigh against it without changing provider.

The same job on other clouds

WAF & Edge Security on other providers. Useful when the cloud is still open, or when you are pricing a second one. How far a comparison like that can be trusted is covered in comparing clouds.

Installing it

module "gcp_cloud_armor" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-cloud-armor/gcp"
  version = "1.1.0"
}

A registry token is required for the download itself. Installing through the registry protocol has the two credential steps.