# TLS Termination, WAF and CORS — API Gateway and Service Mesh

Source: https://www.geekswithgeeks.com/en/api-gateway-service-mesh/s-tls-waf-cors

> Terminate TLS at the edge, add a web application firewall and handle cross-origin requests correctly.

## Edge hardening

**TLS termination** at the gateway decrypts HTTPS once, manages certificates in one place (with automatic renewal, for example via ACME/Let's Encrypt) and lets you enforce modern protocol versions and HSTS. Traffic behind the gateway should still be encrypted if it crosses networks you do not fully trust, which is exactly what a mesh's mTLS provides. A **WAF** (web application firewall, such as ModSecurity rules or a cloud WAF) blocks common attacks like SQL injection patterns and known bad bots, but it is a safety net, not a replacement for secure code. **CORS** headers (`Access-Control-Allow-Origin` and friends) tell browsers which other origins may call your API; allow specific origins instead of `*` for credentialed requests, and handle `OPTIONS` pre-flight requests. Also set request **size and timeout limits** to blunt slow-client and oversized-body attacks.

## Hardening settings (illustrative)

Typical nginx directives; certificate paths and origins are placeholders. Not run here.

```nginx
server {
  listen 443 ssl;
  ssl_certificate     /etc/ssl/api.example.com.crt;
  ssl_certificate_key /etc/ssl/api.example.com.key;
  ssl_protocols TLSv1.2 TLSv1.3;
  add_header Strict-Transport-Security "max-age=31536000" always;

  client_max_body_size 1m;
  client_body_timeout  10s;

  location /api/ {
    add_header Access-Control-Allow-Origin "https://app.example.com" always;
    proxy_pass http://backend/;
  }
}
```

**Quiz:** Why avoid `Access-Control-Allow-Origin: *` for credentialed APIs?

- [ ] It disables caching only
- [ ] It slows TLS
- [ ] It is not valid HTTP
- [x] It would let any website call the API from a user's browser

*Answer:* It would let any website call the API from a user's browser. Wildcard origins weaken the browser protection that CORS provides.
