F5 Hardened Release 1 is available. Staying current is one of the most important steps you can take to protect your environment.Learn more

Architecting application-adjacent WAF defense in Google Cloud

F5 ADSP | August 14, 2026

In modern cloud-native architectures, enterprise applications are increasingly distributed, modular, and dynamic. As workloads migrate to Google Cloud, relying solely on edge security or traditional centralized security designs where all application traffic is hair-pinned through distant security gateways creates latency bottlenecks, operational complexity, and visibility gaps.

To address these challenges, cloud architects and SecOps teams are adopting a defense-in-depth strategy that incorporates application-adjacent security models. By pairing edge protection with deep web application firewall (WAF) inspection embedded directly into the application delivery layer such as via F5 Application Delivery Service for Google Cloud (formerly F5 NGINXaaS for Google Cloud), a component of the broader F5 Application Delivery and Security Platform (ADSP), organizations enforce granular, context-aware defense right at the workload boundary.

Relying solely on edge security leaves critical gaps. By pairing global protection with application-adjacent WAF, you enforce granular, context-aware defense right at the workload boundary, achieving precision while eliminating latency bottlenecks.

Rethinking WAF placement: The power of layered defense in the cloud

Edge security services, such as CDNs and global DDoS scrubbing centers, play a vital first role in a cloud security strategy by stopping volumetric attacks, botnets, and broad malicious traffic far from your cloud environment. However, a single security layer at the edge is rarely sufficient for complex, API-driven distributed application architectures.

A multi-layered defense model addresses key gaps that edge-only security cannot solve on its own:

  1. Complementary threat mitigation: While global edge services mitigate volumetric DDoS and high-velocity attacks, application-adjacent WAF provides deep, workload-specific Layer 7 inspection tuned directly to the application logic.
  2. Preserving rich context: As traffic reaches backend services, application-adjacent WAF leverages localized routing metadata, protocol specifics, and precise URI structures to make accurate security decisions without false positives.
  3. Internal boundary enforcement: In multi-tenant cloud environments or hybrid setups, edge security cannot inspect traffic originating within the cloud network or passing between internal endpoints. Application-adjacent security establishes zero-trust micro-boundaries around each backend target.
  4. Minimized latency and hair-pinning: By placing application-specific inspection directly in the local application delivery layer in Google Cloud, traffic avoids additional hairpin hops back through centralized security gateways, optimizing performance for latency-sensitive services.

Architectural patterns for layered app-adjacent protection

Integrating WAF capabilities natively into the F5 Application Delivery Service SaaS proxy layer enables powerful architectural patterns designed for distributed cloud environments.

By integrating in-line inspection at the application ingress, you can analyze Layer 7 traffic directly at the application gateway within Google Cloud. This mechanism immediately filters out critical threats, such as OWASP Top 10 vulnerabilities, business logic abuse, and protocol anomalies, before they can ever reach upstream API backends and containerized workloads.

By decoupling control, SecOps and security engineering teams can define global baseline security policies while DevOps and platform engineering teams manage localized routing and application logic. Security becomes an intrinsic, continuous control with enforced consistency in the application delivery pipeline.

Application proximity allows implementation of workload-tuned security policies; WAF rules can be tailored precisely to the specific target being protected. Whether it's an enterprise workload, containerized API endpoint, AI inference, or another service, this granular approach ensures robust protection without risking disruption to adjacent services.

Unified ADCaaS and WAF: Operational and economic synergy

Combining Application Delivery Controller as a Service (ADCaaS) with advanced WAF inspection into a single integrated control point, as a part of F5 ADSP, delivers substantial operational and financial benefits within a layered defense architecture:

  • Reduced operational complexity: Consolidating application routing, load balancing, and WAF inspection into a unified service eliminates point-solution sprawl. Operations teams manage a single control surface with standardized declarative configurations, reducing management overhead and human error.
  • Streamlined automation and CI/CD: Native integration allows application delivery and WAF rulesets to be provisioned together via Infrastructure as Code (IaC) tools like Terraform. Security updates deploy seamlessly alongside application releases without out-of-band policy syncs.
  • Economic advantages and lower TCO: Consolidating application delivery and security controls in-cloud significantly reduces licensing overhead and avoids unnecessary cloud egress and cross-zone data transfer costs. Organizations achieve lower total cost of ownership (TCO) while simplifying cloud consumption and budgeting in Google Cloud.

Building an intrinsic, multi-layered posture

As cloud threat vectors grow more sophisticated, effective defense requires a multi-layered approach that pairs robust edge protection with granular, workload-proximate security. By uniting ADCaaS and WAF capabilities in close proximity to application workloads in Google Cloud, enterprise platform and architecture teams deliver high-speed, resilient application delivery backed by comprehensive, multi-layer defense.

Ready to get started? Visit us on the Google Cloud Marketplace. The WAF feature is currently available in preview as an add-on for F5 Application Delivery Service for Google Cloud. The preview capabilities include the ability to select default policy for out-of-box protection from OWASP Top 10 threats.

Share

About the Authors

Ilya Krutov
Ilya KrutovSenior Product Marketing Manager | F5 NGINX

More blogs by Ilya Krutov
Brian Ehlert
Brian EhlertDirector of Product Management

More blogs by Brian Ehlert

Related Blog Posts

Securing F5 NGINX in the age of AI
F5 ADSP | 07/08/2026

Securing F5 NGINX in the age of AI

How F5 is applying AI-driven security practices across the F5 NGINX portfolio to help deliver safer, more resilient software.

From dashboard fatigue to operational excellence: Why XOps needs F5 Insight for ADSP
F5 ADSP | 03/26/2026

From dashboard fatigue to operational excellence: Why XOps needs F5 Insight for ADSP

Learn how F5 Insight for ADSP lays the visibility foundation for XOps—turning fragmented signals across applications and infrastructure into actionable intelligence.

The hidden cost of unmanaged AI infrastructure
F5 ADSP | 01/20/2026

The hidden cost of unmanaged AI infrastructure

AI platforms don’t lose value because of models. They lose value because of instability. See how intelligent traffic management improves token throughput while protecting expensive GPU infrastructure.

Govern your AI present and anticipate your AI future
F5 ADSP | 12/18/2025

Govern your AI present and anticipate your AI future

Learn from our field CISO, Chuck Herrin, how to prepare for the new challenge of securing AI models and agents.

F5 recognized as one of the Emerging Visionaries in the Emerging Market Quadrant of the 2025 Gartner® Innovation Guide for Generative AI Engineering
F5 ADSP | 11/25/2025

F5 recognized as one of the Emerging Visionaries in the Emerging Market Quadrant of the 2025 Gartner® Innovation Guide for Generative AI Engineering

We’re excited to share that F5 has been recognized in 2025 Gartner Emerging Market Quadrant(eMQ) for Generative AI Engineering.

Self-Hosting vs. Models-as-a-Service: The Runtime Security Tradeoff
F5 ADSP | 05/01/2025

Self-Hosting vs. Models-as-a-Service: The Runtime Security Tradeoff

As GenAI systems continue to move from experimental pilots to enterprise-wide deployments, one architectural choice carries significant weight: how will your organization deploy runtime-based capabilities?