okustera_apisix_route (Resource)
The okustera_apisix_route resource configures high-performance ingress routing rules on the Apache APISIX Gateway (apisix namespace), mapping public domain hostnames and URL paths to backend Kubernetes services or serverless functions with automated SSL/TLS certificate provisioning, Web Application Firewall (WAF) inspection, CORS, and rate limiting plugins.
Key Features
- Automated SSL/TLS Termination: When
tls_enabled = true, the provider dynamically provisionsCertificateandApisixTlsresources viacert-manager(Let's Encrypt or private CA ClusterIssuer) and configures automatic HTTP to HTTPS (308 Permanent Redirect) with HSTS. - Web Application Firewall (WAF): Built-in ModSecurity engine with OWASP Core Rule Set (CRS 3.3+) protection against SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and malicious payloads. Supports
DetectionOnly(monitoring and audit logging) andBlocking(rejection with HTTP 403 Forbidden). - Traffic Control & Governance: Granular token bucket rate limiting (requests per minute and burst capacity) and cross-origin resource sharing (CORS) headers.
- Flexible Upstream Targets: Route to Kubernetes ClusterIP services or serverless functions (
okustera_function) across any tenant namespace.
Example Usage
1. Production API Route with Automated TLS and WAF
resource "okustera_apisix_route" "api_v1" {
name = "customer-portal-api"
domain = "api.okustera.com"
path = "/api/v1/*"
upstream = {
service_name = "customer-service"
port = 8080
timeout = 15
}
# Automated SSL/TLS with cert-manager
tls_enabled = true
cluster_issuer = "letsencrypt-prod"
# OWASP ModSecurity WAF Protection
waf_enabled = true
waf_mode = "DetectionOnly" # Or "Blocking" for active mitigation
# Traffic Governance & Security
rate_limit = {
requests_per_minute = 300
burst = 50
}
cors_enabled = true
}
2. Mission-Critical Financial Route with Active WAF Blocking
resource "okustera_apisix_route" "payments" {
name = "payment-gateway-api"
domain = "pay.okustera.com"
path = "/checkout/v2/*"
upstream = {
service_name = "payment-processor"
port = 8443
timeout = 30
}
tls_enabled = true
cluster_issuer = "letsencrypt-prod"
# Actively block SQLi, XSS, and exploit attempts
waf_enabled = true
waf_mode = "Blocking"
rate_limit = {
requests_per_minute = 60
burst = 10
}
cors_enabled = false
}
3. Serverless Function Ingress Route
resource "okustera_apisix_route" "webhook_lake" {
name = "webhook-ingest-route"
domain = "hooks.okustera.com"
path = "/api/v1/webhooks"
service_name = "okustera-function-webhook-lake-ingest"
service_port = 8080
target_namespace = "tenant-prod"
tls_enabled = true
waf_enabled = true
waf_mode = "DetectionOnly"
}
Schema
Required
name(String) Unique route identifier name.
Optional
Route Matching
domain(String) Primary domain name or Host header to match (e.g.api.okustera.com).host(String) Host header alias (alternative todomain).path(String) Primary URI path pattern (defaults to/*). Supports prefix matches such as/api/v1/*.paths(List of String) Additional list of URI path patterns for multi-path routing.
Upstream & Backend Target
upstream(Block, Optional) Upstream destination target block:service_name(String, Required) Target Kubernetes service name.port(Number, Required) Port number of the destination Kubernetes service.timeout(Number, Optional) Connect and read timeout in seconds. Defaults to15.
service_name(String, Optional) Direct target service name specification without nested upstream block.service_port(Number, Optional) Direct target service port specification without nested upstream block.target_namespace(String, Optional) Kubernetes namespace where backend service resides. Defaults todefault.
Security & SSL/TLS
tls_enabled(Boolean, Optional) Whether TLS termination and HTTPS redirection are enabled. Defaults tofalse. When enabled, configuresApisixTlsand provisions certificates.cluster_issuer(String, Optional) Thecert-managerClusterIssuer name to use for automatic TLS certificate generation. Defaults toletsencrypt-prod.waf_enabled(Boolean, Optional) Enables Web Application Firewall (ModSecurity engine with OWASP Core Rule Set) on this route. Defaults tofalse.waf_mode(String, Optional) WAF inspection mode:DetectionOnly(Default): Evaluates and logs rule violations to audit logs without dropping packets.Blocking: Immediately terminates malicious requests matching attack signatures with anHTTP 403 Forbiddenresponse.
Traffic Control & Headers
cors_enabled(Boolean, Optional) Automatically configures Cross-Origin Resource Sharing (CORS) headers for browsers. Defaults totrue.rate_limit(Block, Optional) Token bucket rate limiting parameters:requests_per_minute(Number, Optional) Maximum steady-state allowed requests per minute per IP address.burst(Number, Optional) Maximum burst requests allowed above the steady-state rate.
Read-Only Attributes
id(String) Unique identifier assigned to the route.status(String) Live deployment status of the route on the APISIX Gateway (active,syncing,degraded).
Import
Existing APISIX routes can be imported into Terraform using the route ID or route name:
terraform import okustera_apisix_route.api_v1 customer-portal-api