Kubernetes Policy Lifecycle Management
Policy Lifecycle Management (PLM) provides a declarative way to manage F5 WAF for NGINX security policies in Kubernetes.
PLM uses the Kubernetes operator pattern to automate the lifecycle of F5 WAF security artifacts. You do not need to compile policies manually with the F5 WAF compiler tool. Instead, you define policies as Kubernetes custom resources (APPolicy, APLogConf, and APUserSig).
The PLM Policy Controller compiles the custom resources automatically and publishes the compiled bundles to an in-cluster storage service. The data plane then downloads the bundles from storage and enforces them at request time. PLM also delivers automated attack signature updates.
PLM supersedes the early access preview previously known as Kubernetes operations improvements. If you deployed the early access preview, migrate your configuration using the Deployment options.
To use PLM in your cluster, deploy it with your chosen Kubernetes traffic management solution:
- F5 NGINX Ingress Controller: For environments that use standard Kubernetes Ingress or NGINX
VirtualServerresources, see Install NGINX Ingress Controller with F5 WAF for NGINX using PLM. - F5 NGINX Gateway Fabric: For environments that use the Kubernetes Gateway API (
GatewayandHTTPRouteresources), see Get started with F5 WAF for NGINX (PLM).