AtfWaf creates a REGIONAL WebACL and associates it to your REST API stage (or AppSync API) using the stage/API ARN read from SSM — keeping the WebACL in its own stack, decoupled from the API’s lifecycle.
When to reach for it
Section titled “When to reach for it”Use it to put a WAF in front of your API. See Security Perimeter.
Composition
Section titled “Composition”Composed by a SecurityStack in the examples; associates via the SSM stage ARN.
Props & API
Section titled “Props & API”AtfWaf extends its CDK counterpart, and its props extend Omit<CdkProps> — every CDK prop the framework doesn’t own is available directly, with full autocomplete. The complete, always-current prop interface is generated from the source in the API reference. See also Axis IS CDK for the extend-never-wrap contract.
© 2026 Axis Tech. Powered by axis-tech.co.