F5 argues for application-adjacent WAF defense in Google Cloud
F5's Google Cloud WAF guidance is a useful counterweight to edge-only security thinking. Global edge defenses are still necessary for volumetric attacks and broad filtering, but many application-layer decisions need workload context that only exists closer to the service boundary.
The architecture makes the strongest case for distributed cloud environments where traffic may be internal, multi-tenant, or API-heavy. In those cases, pairing edge controls with application-adjacent inspection can improve precision without forcing every path through a distant central gateway.
Source: Architecting application-adjacent WAF defense in Google Cloud
Community discussion