- Support
- Integrations
- Web Application Firewall
Web Application Firewall
Oracle Cloud integration · 17 node(s).
00Overview
Manage Oracle Cloud Web Application Firewall from a flow — create reusable WAF policies, attach them to your load balancers to shield web apps from malicious traffic, and move, rename or tear down firewalls and policies as your environment changes. Maintain the network address lists that policies use to allow or block ranges of IP addresses, and browse the Oracle-managed protection capabilities available in a compartment. Every create, update and delete runs asynchronously, returning a work-request id you can poll until the resource becomes active.
Every field below is exactly what you see in the Flomation editor. Fields marked ● live picker let you choose from a list pulled live from your account — no IDs to look up.
01Connecting Web Application Firewall
- In the Oracle Cloud Console, open the profile menu (top-right) → User settings, then under Resources choose API keys → Add API key and generate or upload an RSA key pair — OCI then shows a Configuration file preview containing your Tenancy OCID, User OCID, Key Fingerprint and Region.
- In the node, pick an Authentication method: Connect Oracle Cloud (the default) lets you select an already-connected account in the Oracle Cloud connection field and auto-fills the signing details for you, while API signing key (advanced) lets you enter each field by hand.
- For the advanced method, paste the console values into Tenancy OCID, User OCID, Region (a plain identifier such as
uk-london-1) and Key Fingerprint, and set Compartment OCID to the compartment that holds your WAF policies, firewalls and load balancers. - Store the API signing private key (the full PEM, including the
BEGIN/ENDlines) as a Flomation environment secret (e.g.waf_secret) and pick it in the node's Private Key (PEM) field; if the key is encrypted, store its passphrase as a secret too and select it in Private Key Passphrase.
| Field | Type | Details | |
|---|---|---|---|
| Authentication | string | Connect Oracle Cloud, API signing key (advanced) | |
| Oracle Cloud connection | credential | Pick a connected Oracle Cloud account | |
| Region | string | e.g. uk-london-1 | |
| Private Key (PEM) | secret | The API signing private key — full PEM, incl. BEGIN/END lines | |
| Private Key Passphrase | secret | Only if the key is encrypted (optional) | |
| Tenancy OCID | string | ocid1.tenancy.oc1..aaaa… | |
| User OCID | string | ocid1.user.oc1..aaaa… | |
| Key Fingerprint | string | aa:bb:cc:… fingerprint of the uploaded API key |
Pick an Environment on your flow (Flow Settings → Environment) so the secret resolves. Secret fields never show the value — they reference ${secrets.your_secret}.
02Network
OCI WAF: Create Network Address List
oracle/waf/network_address_list_create · Action
Create a WAF network address list from a comma-separated set of IP address prefixes (CIDR). Returns a work-request id — the creation is asynchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Display Name | string | A name for the network address list (optional) | |
| Addresses (CIDR, comma-separated) | string | Required | e.g. 192.0.2.0/24, 203.0.113.5/32, ::/0 |
Returns: tool_result, work_request_id, success, error
OCI WAF: Delete Network Address List
oracle/waf/network_address_list_delete · Action
Delete a WAF network address list by its OCID. Returns a work-request id — the removal is asynchronous.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Network Address List OCID | string | Required | ocid1.wafnetworkaddresslist.oc1..aaaa… of the list to delete |
Returns: tool_result, id, work_request_id, success, error
OCI WAF: Get Network Address List
oracle/waf/network_address_list_get · Action
Fetch a single WAF network address list by its OCID — its address type, addresses and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Network Address List OCID | string | Required | ocid1.wafnetworkaddresslist.oc1..aaaa… |
Returns: tool_result, network_address_list, id, lifecycle_state, success, error
OCI WAF: List Network Address Lists
oracle/waf/network_address_list_list · Action
List the WAF network address lists in a compartment. Optionally filter by exact display name. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only lists with this exact name (optional) | |
| Page Size | string | Max items per page (optional) |
Returns: tool_result, network_address_lists, count, truncated, success, error
03Policy
OCI WAF: Change Policy Compartment
oracle/waf/policy_change_compartment · Action
Move a WAF policy into a different compartment — the policy keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Policy OCID | string | Required | ocid1.webappfirewallpolicy.oc1..aaaa… (the policy to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the policy) |
Returns: tool_result, id, destination_compartment_id, success, error
OCI WAF: Create Policy
oracle/waf/policy_create · Action
Create an empty Web Application Firewall policy with a display name. Returns a work-request id — poll Get Policy until ACTIVE, then add rules.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Display Name | string | A name for the policy (optional) |
Returns: tool_result, work_request_id, success, error
OCI WAF: Delete Policy
oracle/waf/policy_delete · Action
Delete a Web Application Firewall policy by its OCID. Asynchronous — returns a work-request id; the policy must not be attached to any firewall.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Policy OCID | string | Required | ocid1.webappfirewallpolicy.oc1..aaaa… of the policy to delete |
Returns: tool_result, id, work_request_id, success, error
OCI WAF: Get Policy
oracle/waf/policy_get · Action
Fetch a single Web Application Firewall policy by its OCID — its display name, actions count and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Policy OCID | string | Required | ocid1.webappfirewallpolicy.oc1..aaaa… |
Returns: tool_result, policy, id, lifecycle_state, success, error
OCI WAF: List Policies
oracle/waf/policy_list · Action
List the Web Application Firewall policies in a compartment, optionally filtered by exact display name and lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only policies with this exact name (optional) | |
| Lifecycle State | string | Only policies in this state (optional) — choices: Creating, Updating, Active, Deleting, Deleted, Failed | |
| Page Size | string | Items per page, 1–1000 (optional) |
Returns: tool_result, policies, count, truncated, success, error
OCI WAF: Update Policy
oracle/waf/policy_update · Action
Partially update a Web Application Firewall policy — rename it via the display name you supply; blank fields are left unchanged. Asynchronous: returns a work-request id, poll Get Policy until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Policy OCID | string | Required | ocid1.webappfirewallpolicy.oc1..aaaa… — the policy to update |
| Display Name | string | New name (leave blank to keep unchanged) |
Returns: tool_result, id, work_request_id, success, error
04Protection
OCI WAF: List Protection Capabilities
oracle/waf/protection_capability_list · Action
List the OCI-managed protection capabilities available to WAF policies in a compartment. Optionally filter by unique key or capability type. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Capability Key Filter | string | Only the capability with this unique key, e.g. 920320 (optional) | |
| Capability Type | string | All types when unset (optional) — choices: Request Protection, Response Protection | |
| Page Size | string | Items per page (optional) |
Returns: tool_result, capabilities, count, truncated, success, error
05Web
OCI WAF: Change Web App Firewall Compartment
oracle/waf/web_app_firewall_change_compartment · Action
Move a WAF Web App Firewall into a different compartment — it keeps its OCID, only its compartment placement changes.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Web App Firewall OCID | string | Required | ocid1.webappfirewall.oc1..aaaa… (the firewall to move) |
| Destination Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (where to move the firewall) |
Returns: tool_result, id, destination_compartment_id, success, error
OCI WAF: Create Web App Firewall
oracle/waf/web_app_firewall_create · Action
Attach a WAF policy to a load balancer by creating a load-balancer-backed Web App Firewall. Returns a work-request id — poll Get Web App Firewall until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| WAF Policy OCID | string | Required | ocid1.webappfirewallpolicy.oc1..aaaa… — the policy to attach |
| Load Balancer OCID | string | Required | ocid1.loadbalancer.oc1..aaaa… — the backend to protect |
| Display Name | string | A name for the Web App Firewall (optional) |
Returns: tool_result, work_request_id, success, error
OCI WAF: Delete Web App Firewall
oracle/waf/web_app_firewall_delete · Action
Delete a Web Application Firewall by its OCID — it detaches from its backend. Returns a work-request id to poll for completion.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Web App Firewall OCID | string | Required | ocid1.webappfirewall.oc1..aaaa… of the firewall to delete |
Returns: tool_result, id, work_request_id, success, error
OCI WAF: Get Web App Firewall
oracle/waf/web_app_firewall_get · Action
Fetch a single Web Application Firewall by its OCID — its policy, backend and lifecycle state.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Web App Firewall OCID | string | Required | ocid1.webappfirewall.oc1..aaaa… |
Returns: tool_result, web_app_firewall, id, lifecycle_state, success, error
OCI WAF: List Web App Firewalls
oracle/waf/web_app_firewall_list · Action
List the Web Application Firewalls in a compartment. Optionally filter by exact display name or lifecycle state. Walks pagination up to a safe cap.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… (use the tenancy OCID for the root) |
| Display Name Filter | string | Only firewalls with this exact display name (optional) | |
| Lifecycle State | string | Only firewalls in this state (optional) — choices: Any, Creating, Updating, Active, Deleting, Deleted, Failed | |
| Page Size | string | Max results per page (optional) |
Returns: tool_result, web_app_firewalls, count, truncated, success, error
OCI WAF: Update Web App Firewall
oracle/waf/web_app_firewall_update · Action
Partially update a Web Application Firewall — change only the display name and/or attached policy you supply; blank fields are left unchanged. Asynchronous: returns a work-request id, poll Get Web App Firewall until ACTIVE.
| Field | Type | Details | |
|---|---|---|---|
| Compartment OCID | string | Required | ocid1.compartment.oc1..aaaa… |
| Web App Firewall OCID | string | Required | ocid1.webappfirewall.oc1..aaaa… — the firewall to update |
| Display Name | string | New name (leave blank to keep unchanged) | |
| Policy OCID | string | ocid1.webappfirewallpolicy.oc1..aaaa… — new policy to attach (leave blank to keep unchanged) |
Returns: tool_result, id, work_request_id, success, error
06Notes & Limitations
Behaviours and constraints worth knowing before you build with these nodes.
- Create Policy, Create Web App Firewall, and every update and delete run asynchronously: they hand back a work-request id and the resource only reaches ACTIVE after a short delay, so poll the matching Get action before you rely on or remove it.
- Create Web App Firewall only attaches an existing policy to an existing load balancer, so both the load balancer and the WAF policy must already exist in the same region before you can protect the application.
- Create Policy produces an empty policy with no protection rules, and these actions only set names and manage which policy a firewall uses; the rules that actually inspect and filter traffic must be configured in Oracle Cloud itself.
- Deleting a policy is rejected while it is still attached to a Web App Firewall, so delete the firewall or repoint it onto another policy first.
- A Compartment OCID is required on every action, and the list actions return only the resources in that single compartment rather than across the whole tenancy.