Lesson 11 / 26
TLS Termination, WAF and CORS
Terminate TLS at the edge, add a web application firewall and handle cross-origin requests correctly.
Edge hardening
TLS termination at the gateway decrypts HTTPS once, manages certificates in one place (with automatic renewal, for example via ACME/Let's Encrypt) and lets you enforce modern protocol versions and HSTS. Traffic behind the gateway should still be encrypted if it crosses networks you do not fully trust, which is exactly what a mesh's mTLS provides. A WAF (web application firewall, such as ModSecurity rules or a cloud WAF) blocks common attacks like SQL injection patterns and known bad bots, but it is a safety net, not a replacement for secure code. CORS headers (Access-Control-Allow-Origin and friends) tell browsers which other origins may call your API; allow specific origins instead of * for credentialed requests, and handle OPTIONS pre-flight requests. Also set request size and timeout limits to blunt slow-client and oversized-body attacks.
Hardening settings (illustrative)
Typical nginx directives; certificate paths and origins are placeholders. Not run here.
server {
listen 443 ssl;
ssl_certificate /etc/ssl/api.example.com.crt;
ssl_certificate_key /etc/ssl/api.example.com.key;
ssl_protocols TLSv1.2 TLSv1.3;
add_header Strict-Transport-Security "max-age=31536000" always;
client_max_body_size 1m;
client_body_timeout 10s;
location /api/ {
add_header Access-Control-Allow-Origin "https://app.example.com" always;
proxy_pass http://backend/;
}
}Quick check: Why avoid `Access-Control-Allow-Origin: *` for credentialed APIs?
- It disables caching only
- It slows TLS
- It is not valid HTTP
- It would let any website call the API from a user's browser
Answer
It would let any website call the API from a user's browser — Wildcard origins weaken the browser protection that CORS provides.