Choose a setup
You configure Network Firewall with variables in the bootstrap Terraform you run during deployment. The bootstrap README walks you through setting them. Use this page to choose a setup and confirm the right variables are set for it. See the variable reference for every variable. Pick one of three setups:
You can add Network Firewall during your initial deployment or later. To add it or change setups later, update the variables and re-apply the bootstrap Terraform. Superblocks wires the firewall into your instance at the next deployment.
Bring your own firewall
Use a Network Firewall you already deploy and manage. Cloud-Prem routes outbound traffic from each availability zone’s public subnet through your firewall endpoint instead of directly to the internet gateway. This applies to both the control plane and Superblocks-managed data planes. The bootstrap Terraform creates the Cloud-Prem VPC, so set up the firewall in this order:- Apply the bootstrap Terraform without any firewall variables. This creates the Cloud-Prem VPC.
- Deploy your Network Firewall with an endpoint in the Cloud-Prem VPC for each availability zone Cloud-Prem uses.
-
Set
firewall_endpoint_idsto a map of availability zone ID to firewall endpoint ID. Use AZ IDs such asusw2-az1, not AZ names such asus-west-2a. - Re-apply the bootstrap Terraform. Superblocks wires the firewall into your instance at the next deployment.
enable_network_firewall when you bring your own firewall. The two options can’t be combined.
Bootstrap-managed firewall
Have the bootstrap Terraform create the firewall for you. It creates firewall subnets and endpoints in the Cloud-Prem VPC and routes outbound traffic, and the return traffic from the internet gateway, through them. It filters control plane traffic only, not traffic from Superblocks-managed data planes.-
Set
enable_network_firewalltotrue. -
Add a
cidr_firewallentry with exactly one IPv4 CIDR to each availability zone innetwork.subnets: - Apply the bootstrap Terraform. Superblocks wires the firewall into your instance at the next deployment.
Use the default allowlist
With a bootstrap-managed firewall, you can have the bootstrap enforce the Superblocks default allowlist. Outbound control plane traffic is then blocked unless it’s going to an allowed domain. Traffic from Superblocks-managed data planes isn’t filtered.
To see the allowlist the firewall is enforcing, run:
Increase the rule group capacity
AWS fixes a rule group’s capacity when it’s created. Raisenetwork_firewall_default_rule_group_capacity before adding enough extra domains to exceed it. Changing the capacity replaces the rule group, so apply it in two steps:
- Set
enable_network_firewall_default_rule_groupstofalseand apply. - Set the new capacity, set
enable_network_firewall_default_rule_groupsback totrue, and apply again.
Required outbound domains
The Cloud-Prem control plane needs to reach these domains. The default allowlist includes all of them. If you manage your own rules, allow them yourself. Replace<region> with your Cloud-Prem AWS region.
Also allow the domains your deployment reaches beyond the Superblocks platform, such as your identity provider, the APIs and databases your apps connect to, and any observability destinations you send telemetry to.

