Enterprise edge & WAF platform
- Context
- A public-facing estate served through a shared ingress layer, where every application depended on the same traffic path.
- Problem
- Traffic policy, TLS and health checking were handled per application, so a change in one place could take neighbours down with it.
- Work
- Designed and built a multi-node traffic layer with WAF policy, TLS termination and automated health checks, then moved applications onto it in stages.
- Technology
- Nginx, HAProxy, WAF rule sets, TLS.
- Scope
- Architecture, implementation, migration, operation.


