Envoy Application Security (Injector) | Check Point WAF

CloudGuard WAF for Envoy Gateway

CloudGuard WAF for Envoy Gateway is deployed using a Helm chart that includes a namespace-level webhook. This webhook monitors changes to the Envoy Gateway deployment and automatically injects the required WAF agent and attachment into the gateway pods. The configuration of Envoy Gateway follows standard practices for defining gateway resources and routing traffic to your services.

Prerequisites

Installation

Step 1 – Create profile and copy token

Create any profile in the CloudGuard UI, copy the agent token, and ensure the policy is set to Enforce.

Step 2 – Label the gateway namespace

kubectl label namespace <envoy gateway namespace> inject-waf-attachment="true" --overwrite

Step 3 – Label the Deployment

Ensure your Envoy Gateway Deployment includes the labels required by the webhook.objectSelector:

Example:

kubectl label deployment <envoy gateway deployment name> <label name>=<label value> -n <envoy gateway namespace> --overwrite

Step 4 – Install the webhook using Helm

helm install cloudguard-webhook \
oci://registry-1.docker.io/checkpoint/cloudguard-waf-injector \
--version <version> \
--set webhook.objectSelector.labelValue=<label value> \
--set webhook.objectSelector.labelName=<label name> \
--set appsec.persistence.enabled=false \
--set kind=envoy_gateway \
--set webhook.envoyGatewayImageName=envoy \
--set webhook.gatewayResourceNamespace=<gateway resource namespace> \
--set webhook.gatewayResourceName=<gateway resource name> \
--set appsec.agentToken=<token> \
-n <envoy gateway namespace>

Replace with the latest tag in this repository - https://hub.docker.com/r/checkpoint/cloudguard-waf-injector/tags

Step 5 – Restart the gateway Deployment

kubectl rollout restart deployment/<envoy gateway deployment name> -n <envoy gateway namespace>