---
name: azion-install-bot-manager-lite
description: >-
  Install Bot Manager Lite from Azion Marketplace, create the function instance and the Rules Engine rule that run it, and bind the firewall to a workload.
---

# Install Bot Manager Lite

You install [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/) from Azion Marketplace and put it in the request path of your application, from Azion Console.

Five objects have to exist before a request is scored: the installed function, a [Firewall](/en/documentation/platform/firewall/) carrying the **Functions** module, a function instance holding the arguments, a Rules Engine rule that runs that instance, and a workload bound to the firewall. Each stage below creates one of them.

This guide is the long path, and it starts from an account with nothing configured. For the same instance and rule written with the Azion CLI or the Azion API, and for the request that proves the function scored something, refer to [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).

---

## Prerequisites

- An Azion account. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An application served by a [workload](/en/documentation/platform/workloads/), on a domain of the form `<id>.map.azionedge.net` or on a domain of your own.
- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized, for the last stage.
- Turning on a product or a module can generate usage costs. For the metrics Bot Manager is billed on, refer to [Pricing](/en/documentation/fundamentals/pricing/#bot-manager).

---

## Install the integration from Marketplace

The function is installed once per account, and the install runs in Azion Console. To install it:

1. **Open Marketplace**

   Access [Azion Console](https://console.azion.com/) > **Marketplace**.

2. **Find the integration**

   Enter `Bot Manager Lite` in the search field, then select the integration's card. Browsing the cards and the category filters reaches the same page.

3. **Select Install**

The card shows `Successfully installed!` and `Latest version installed!`, and the function appears in the **Function** list of the **Create Instance** drawer. In Azion Console > **Functions**, a **Vendor** column marks it as a Marketplace install.

---

## Create the firewall

The firewall is where the function is instanced and where the rule that runs it lives. To create one:

1. **Open the Firewalls page**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then create a firewall.

2. **Name the firewall**

   In the **General** section, enter a **Name**. For example: `storefront-firewall`.

3. **Confirm that the Functions module is turned on**

   In the **Modules** section, the **Functions** switch is what lets a firewall run an installed function. A firewall created with the Azion CLI has it turned on already.

4. **(Optional) Turn on Debug Rules**

   In the **Debug Rules** section, turn on the **Active** switch. The firewall then records which Rules Engine rules ran for each request, which is what tells you whether the rule below fired.

5. **Save the firewall**

The firewall carries a **Functions Instances** tab for as long as the **Functions** module stays turned on. For every setting on this form, refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).

---

## Create the function instance

An instance takes its whole configuration from one JSON object. Bot Manager Lite ships a default for the arguments it reads, so an instance that sets none of them runs at a `threshold` of `30`, an `action` of `deny`, `internal_logs` at `0`, and a `log_tag` of `bot-manager-instance`.

Four arguments are enough for a first instance:

```json
{
  "threshold": 30,
  "action": "deny",
  "internal_logs": 2,
  "log_tag": "storefront-bots"
}
```

`threshold` is the score a request reaches before `action` is applied to it. `internal_logs` at `2` writes a report line for every request, including one that scores `0`, which is how the first days of traffic become readable. `log_tag` names this instance in those lines, so give each instance a tag of its own. Setting `action` to `allow` until you know how your own traffic scores keeps the instance from refusing a customer; for that window and what it costs, refer to [Firewall best practices](/en/documentation/platform/firewall/best-practices/#bot-manager).

> **Caution**
>
> Nothing validates the object. Every key is stored and read back exactly as it was typed, including a key the function never reads. Writing `thresold` in place of `threshold` leaves the threshold at `30`, and no interface reports a problem.

To create the instance:

1. **Open the Functions Instances tab**

   In **Firewalls**, select the firewall you created, then select the **Functions Instances** tab.

2. **Select + Function**

   A firewall that carries no instance yet offers the same action as **+ Function Instance**.

3. **Name the instance**

   In the **General** section, enter a **Name**. For example: `bot-manager-lite`.

4. **Select the installed function**

   In the **Function** section, select the Bot Manager Lite function. The selector holds only the functions in the account that run on a firewall.

5. **Enter the arguments**

   In the **Arguments** section, enter the object. The installed function publishes no argument schema, so the section holds a JSON editor and builds no form from one.

6. **Save the instance**

The instance is listed under **Functions Instances**, with its **Name**, **Function**, **Last Editor**, and **Last Modified**. The form carries no **Active** control, because Azion Console creates every instance active.

To change an argument afterwards, select the instance in the same tab, edit the **Arguments** section, and select **Save**. A change reaches Azion's distributed infrastructure in about two minutes, so wait before reading a response as the new configuration. For every argument the object accepts, with its type and its default, refer to [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/#arguments).

---

## Create the rule

The instance scores nothing until a rule runs it. A [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule decides which requests reach the instance, through a **Run Function** behavior that names it. To create the rule:

1. **Open the Rules Engine tab**

   In **Firewalls**, select your firewall, then select the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   Enter a name. For example: `Run Bot Manager Lite on every request`. The description is optional.

4. **Set the criterion**

   In the **Criteria** section, select the `Request Uri` variable, the *starts with* operator, and `/` as the argument.

5. **Add the Run Function behavior**

   In the **Behaviors** section, select **Run Function**. The control beside it carries no label and lists the function instances on this firewall, so select the one you named. A rule carries one **Run Function** behavior.

6. **Save the rule**

The firewall runs the instance on every request it receives.

A second criterion narrows that set. `Request Uri` with the *does not match* operator keeps the instance off requests that carry nothing to score: static assets, and the `/.well-known/` path that automation and web API clients use. For the extensions to exclude and what the exclusion costs, refer to [Firewall best practices](/en/documentation/platform/firewall/best-practices/#bot-manager).

---

## Bind the firewall to the workload

A firewall inspects requests for the workloads bound to it, and the binding sits on the workload's deployment rather than on the workload record. To bind an existing workload, create a deployment that names both the application and the firewall:

```bash
azion create workload-deployment --workload-id <workload-id> --name <deployment-name> \
  --application-id <application-id> --firewall-id <firewall-id> --strategy-type default \
  --active true --current true
```

The command prints the id of the new deployment:

```text
Created Workload Deployment with ID 123456
```

Requests to the workload's domain then reach the firewall, and the rule runs the instance on each one. Give the binding about two minutes before you read anything into a response.

The report line the function writes is where the result of a scored request is. For more information, refer to [Logs](/en/documentation/platform/firewall/bot-manager/logs/).

---

## Next steps

- [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart.md): The same instance and rule in the Azion CLI and the Azion API, and the request that proves a score was written.
- [Arguments](/en/documentation/platform/firewall/bot-manager/arguments.md): Every argument an instance accepts, with its type, its default, and the values it takes.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#bot-manager): How to run an observation window before the instance refuses anything, and how to set a threshold from your own logs.
- [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting.md#bot-manager): What to do when a client is answered in a way you did not expect, or an argument appears to do nothing.
