Lesson 11 / 26

TLS Termination, WAF and CORS

Terminate TLS at the edge, add a web application firewall and handle cross-origin requests correctly.

Edge hardening

TLS termination at the gateway decrypts HTTPS once, manages certificates in one place (with automatic renewal, for example via ACME/Let's Encrypt) and lets you enforce modern protocol versions and HSTS. Traffic behind the gateway should still be encrypted if it crosses networks you do not fully trust, which is exactly what a mesh's mTLS provides. A WAF (web application firewall, such as ModSecurity rules or a cloud WAF) blocks common attacks like SQL injection patterns and known bad bots, but it is a safety net, not a replacement for secure code. CORS headers (Access-Control-Allow-Origin and friends) tell browsers which other origins may call your API; allow specific origins instead of * for credentialed requests, and handle OPTIONS pre-flight requests. Also set request size and timeout limits to blunt slow-client and oversized-body attacks.

Hardening settings (illustrative)

Typical nginx directives; certificate paths and origins are placeholders. Not run here.

server {
  listen 443 ssl;
  ssl_certificate     /etc/ssl/api.example.com.crt;
  ssl_certificate_key /etc/ssl/api.example.com.key;
  ssl_protocols TLSv1.2 TLSv1.3;
  add_header Strict-Transport-Security "max-age=31536000" always;

  client_max_body_size 1m;
  client_body_timeout  10s;

  location /api/ {
    add_header Access-Control-Allow-Origin "https://app.example.com" always;
    proxy_pass http://backend/;
  }
}

Quick check: Why avoid `Access-Control-Allow-Origin: *` for credentialed APIs?

  • It disables caching only
  • It slows TLS
  • It is not valid HTTP
  • It would let any website call the API from a user's browser
Answer

It would let any website call the API from a user's browser — Wildcard origins weaken the browser protection that CORS provides.