SPEC: internet-ready out of the box, with 2026 real-world defaults and minimal required configuration #7

Open
opened 2026-09-23 13:44:29 +02:00 by clawbot · 0 comments
Collaborator

Owner directive (sneak, 2026-09-23 11:37 UTC, in chat). He was replying to a summary of this spec that called smallwebwaf "a filter that only logs by default", a description of the spec's WAF_MODE default of detect. His words, verbatim:

who said anything about "a filter that only logs"? we want this to be internet-ready out of the box with 2026 real world defaults for minimal configuration required.

Where SPEC.md and README.md on main (a0d2c21) contradict it

None of these came from an owner ruling. The spec-writing unit chose them; the 2026-09-21 rulings in #1 do not mention them.

  • WAF_MODE defaults to detect (SPEC.md, configuration surface): a request the Core Rule Set flags is logged and alerted, never refused.
  • RATE_LIMIT_PER_MINUTE, RATE_LIMIT_PER_HOUR and RATE_LIMIT_PER_DAY have no defaults, and the configuration conventions say "an unset limit means that limit is off", so a sidecar started without them does no rate limiting.
  • The rollout section starts every service in MODE=observe with WAF_MODE=detect, and switches to enforce and block only after days of reading logs. The compose examples in both files ship MODE: observe, and the one in SPEC.md also ships WAF_MODE: detect.
  • TRUSTED_PROXIES is marked required. The standing all-apps ruling (2026-09-22) makes its default the RFC 1918 ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16). An explicit list replaces the default, and an explicitly empty list trusts nothing.
  • The ban defaults (3 offences in 10 minutes; bans of 1h, 24h and 7d; permanent after 4) are the model that #2 replaces.

Definition of done

The spec update is the folding unit of #6. It now also folds #2, #3, #4 and #5. It lands as one docs-only PR to next, after which SPEC.md and README.md say:

  1. A sidecar started with only UPSTREAM_URL set protects the app, with every default chosen for an internet-facing service in 2026. Requests the Core Rule Set flags are refused, rate limits apply, and bans follow the model of issue 2. Neither document expects the operator to tune a value before the sidecar is useful.
  2. WAF_MODE defaults to block. MODE=observe and WAF_MODE=detect stay available as settings, but no default, example or rollout step uses them.
  3. TRUSTED_PROXIES is optional and defaults to the RFC 1918 ranges, as above.
  4. Every rate and byte limit has a stated default, and "an unset limit means that limit is off" is gone.
  5. The configuration section marks as required only what cannot have a default, and the compose examples in both files set only that.
  6. The PR is prettier-formatted and merged green.

The repo is paused under the 2026-09-22 priority ruling. The unit runs when the repo resumes.

Model: opus-5-5

Owner directive (sneak, 2026-09-23 11:37 UTC, in chat). He was replying to a summary of this spec that called smallwebwaf "a filter that only logs by default", a description of the spec's `WAF_MODE` default of `detect`. His words, verbatim: > who said anything about "a filter that only logs"? we want this to be internet-ready out of the box with 2026 real world defaults for minimal configuration required. ## Where `SPEC.md` and `README.md` on `main` (`a0d2c21`) contradict it None of these came from an owner ruling. The spec-writing unit chose them; the 2026-09-21 rulings in https://git.eeqj.de/sneak/smallwebwaf/issues/1 do not mention them. - `WAF_MODE` defaults to `detect` (`SPEC.md`, configuration surface): a request the Core Rule Set flags is logged and alerted, never refused. - `RATE_LIMIT_PER_MINUTE`, `RATE_LIMIT_PER_HOUR` and `RATE_LIMIT_PER_DAY` have no defaults, and the configuration conventions say "an unset limit means that limit is off", so a sidecar started without them does no rate limiting. - The rollout section starts every service in `MODE=observe` with `WAF_MODE=detect`, and switches to `enforce` and `block` only after days of reading logs. The compose examples in both files ship `MODE: observe`, and the one in `SPEC.md` also ships `WAF_MODE: detect`. - `TRUSTED_PROXIES` is marked required. The standing all-apps ruling (2026-09-22) makes its default the RFC 1918 ranges (`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`). An explicit list replaces the default, and an explicitly empty list trusts nothing. - The ban defaults (3 offences in 10 minutes; bans of 1h, 24h and 7d; permanent after 4) are the model that https://git.eeqj.de/sneak/smallwebwaf/issues/2 replaces. ## Definition of done The spec update is the folding unit of https://git.eeqj.de/sneak/smallwebwaf/issues/6. It now also folds https://git.eeqj.de/sneak/smallwebwaf/issues/2, https://git.eeqj.de/sneak/smallwebwaf/issues/3, https://git.eeqj.de/sneak/smallwebwaf/issues/4 and https://git.eeqj.de/sneak/smallwebwaf/issues/5. It lands as one docs-only PR to `next`, after which `SPEC.md` and `README.md` say: 1. A sidecar started with only `UPSTREAM_URL` set protects the app, with every default chosen for an internet-facing service in 2026. Requests the Core Rule Set flags are refused, rate limits apply, and bans follow the model of issue 2. Neither document expects the operator to tune a value before the sidecar is useful. 2. `WAF_MODE` defaults to `block`. `MODE=observe` and `WAF_MODE=detect` stay available as settings, but no default, example or rollout step uses them. 3. `TRUSTED_PROXIES` is optional and defaults to the RFC 1918 ranges, as above. 4. Every rate and byte limit has a stated default, and "an unset limit means that limit is off" is gone. 5. The configuration section marks as required only what cannot have a default, and the compose examples in both files set only that. 6. The PR is prettier-formatted and merged green. The repo is paused under the 2026-09-22 priority ruling. The unit runs when the repo resumes. Model: opus-5-5
clawbot self-assigned this 2026-09-23 13:44:29 +02:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/smallwebwaf#7