Skip to main content

okustera_apisix_route (Resource)

The okustera_apisix_route resource configures high-performance ingress routing rules on the Apache APISIX Gateway (apisix namespace), mapping public domain hostnames and URL paths to backend Kubernetes services or serverless functions with automated SSL/TLS certificate provisioning, Web Application Firewall (WAF) inspection, CORS, and rate limiting plugins.


Key Features​

  • Automated SSL/TLS Termination: When tls_enabled = true, the provider dynamically provisions Certificate and ApisixTls resources via cert-manager (Let's Encrypt or private CA ClusterIssuer) and configures automatic HTTP to HTTPS (308 Permanent Redirect) with HSTS.
  • Web Application Firewall (WAF): Built-in ModSecurity engine with OWASP Core Rule Set (CRS 3.3+) protection against SQL Injection (SQLi), Cross-Site Scripting (XSS), Local File Inclusion (LFI), and malicious payloads. Supports DetectionOnly (monitoring and audit logging) and Blocking (rejection with HTTP 403 Forbidden).
  • Traffic Control & Governance: Granular token bucket rate limiting (requests per minute and burst capacity) and cross-origin resource sharing (CORS) headers.
  • Flexible Upstream Targets: Route to Kubernetes ClusterIP services or serverless functions (okustera_function) across any tenant namespace.

Example Usage​

1. Production API Route with Automated TLS and WAF​

resource "okustera_apisix_route" "api_v1" {
name = "customer-portal-api"
domain = "api.okustera.com"
path = "/api/v1/*"

upstream = {
service_name = "customer-service"
port = 8080
timeout = 15
}

# Automated SSL/TLS with cert-manager
tls_enabled = true
cluster_issuer = "letsencrypt-prod"

# OWASP ModSecurity WAF Protection
waf_enabled = true
waf_mode = "DetectionOnly" # Or "Blocking" for active mitigation

# Traffic Governance & Security
rate_limit = {
requests_per_minute = 300
burst = 50
}

cors_enabled = true
}

2. Mission-Critical Financial Route with Active WAF Blocking​

resource "okustera_apisix_route" "payments" {
name = "payment-gateway-api"
domain = "pay.okustera.com"
path = "/checkout/v2/*"

upstream = {
service_name = "payment-processor"
port = 8443
timeout = 30
}

tls_enabled = true
cluster_issuer = "letsencrypt-prod"

# Actively block SQLi, XSS, and exploit attempts
waf_enabled = true
waf_mode = "Blocking"

rate_limit = {
requests_per_minute = 60
burst = 10
}

cors_enabled = false
}

3. Serverless Function Ingress Route​

resource "okustera_apisix_route" "webhook_lake" {
name = "webhook-ingest-route"
domain = "hooks.okustera.com"
path = "/api/v1/webhooks"
service_name = "okustera-function-webhook-lake-ingest"
service_port = 8080
target_namespace = "tenant-prod"

tls_enabled = true
waf_enabled = true
waf_mode = "DetectionOnly"
}

Schema​

Required​

  • name (String) Unique route identifier name.

Optional​

Route Matching​

  • domain (String) Primary domain name or Host header to match (e.g. api.okustera.com).
  • host (String) Host header alias (alternative to domain).
  • path (String) Primary URI path pattern (defaults to /*). Supports prefix matches such as /api/v1/*.
  • paths (List of String) Additional list of URI path patterns for multi-path routing.

Upstream & Backend Target​

  • upstream (Block, Optional) Upstream destination target block:
    • service_name (String, Required) Target Kubernetes service name.
    • port (Number, Required) Port number of the destination Kubernetes service.
    • timeout (Number, Optional) Connect and read timeout in seconds. Defaults to 15.
  • service_name (String, Optional) Direct target service name specification without nested upstream block.
  • service_port (Number, Optional) Direct target service port specification without nested upstream block.
  • target_namespace (String, Optional) Kubernetes namespace where backend service resides. Defaults to default.

Security & SSL/TLS​

  • tls_enabled (Boolean, Optional) Whether TLS termination and HTTPS redirection are enabled. Defaults to false. When enabled, configures ApisixTls and provisions certificates.
  • cluster_issuer (String, Optional) The cert-manager ClusterIssuer name to use for automatic TLS certificate generation. Defaults to letsencrypt-prod.
  • waf_enabled (Boolean, Optional) Enables Web Application Firewall (ModSecurity engine with OWASP Core Rule Set) on this route. Defaults to false.
  • waf_mode (String, Optional) WAF inspection mode:
    • DetectionOnly (Default): Evaluates and logs rule violations to audit logs without dropping packets.
    • Blocking: Immediately terminates malicious requests matching attack signatures with an HTTP 403 Forbidden response.

Traffic Control & Headers​

  • cors_enabled (Boolean, Optional) Automatically configures Cross-Origin Resource Sharing (CORS) headers for browsers. Defaults to true.
  • rate_limit (Block, Optional) Token bucket rate limiting parameters:
    • requests_per_minute (Number, Optional) Maximum steady-state allowed requests per minute per IP address.
    • burst (Number, Optional) Maximum burst requests allowed above the steady-state rate.

Read-Only Attributes​

  • id (String) Unique identifier assigned to the route.
  • status (String) Live deployment status of the route on the APISIX Gateway (active, syncing, degraded).

Import​

Existing APISIX routes can be imported into Terraform using the route ID or route name:

terraform import okustera_apisix_route.api_v1 customer-portal-api