Install Bot Manager Lite
Install Bot Manager Lite from Azion Marketplace, create the function instance and the Rules Engine rule that run it, and bind the firewall to a workload.
You install Bot Manager Lite from Azion Marketplace and put it in the request path of your application, from Azion Console.
Five objects have to exist before a request is scored: the installed function, a Firewall carrying the Functions module, a function instance holding the arguments, a Rules Engine rule that runs that instance, and a workload bound to the firewall. Each stage below creates one of them.
This guide is the long path, and it starts from an account with nothing configured. For the same instance and rule written with the Azion CLI or the Azion API, and for the request that proves the function scored something, refer to Bot Manager quickstart.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload, on a domain of the form
<id>.map.azionedge.netor on a domain of your own. - The Azion CLI installed and authorized, for the last stage.
- Turning on a product or a module can generate usage costs. For the metrics Bot Manager is billed on, refer to Pricing.
Install the integration from Marketplace
The function is installed once per account, and the install runs in Azion Console. To install it:
Access Azion Console > Marketplace.
Enter Bot Manager Lite in the search field, then select the integration’s card. Browsing the cards and the category filters reaches the same page.
The card shows Successfully installed! and Latest version installed!, and the function appears in the Function list of the Create Instance drawer. In Azion Console > Functions, a Vendor column marks it as a Marketplace install.
Create the firewall
The firewall is where the function is instanced and where the rule that runs it lives. To create one:
Access Azion Console > Firewalls, then create a firewall.
In the General section, enter a Name. For example: storefront-firewall.
In the Modules section, the Functions switch is what lets a firewall run an installed function. A firewall created with the Azion CLI has it turned on already.
In the Debug Rules section, turn on the Active switch. The firewall then records which Rules Engine rules ran for each request, which is what tells you whether the rule below fired.
The firewall carries a Functions Instances tab for as long as the Functions module stays turned on. For every setting on this form, refer to Set a firewall’s main settings.
Create the function instance
An instance takes its whole configuration from one JSON object. Bot Manager Lite ships a default for the arguments it reads, so an instance that sets none of them runs at a threshold of 30, an action of deny, internal_logs at 0, and a log_tag of bot-manager-instance.
Four arguments are enough for a first instance:
threshold is the score a request reaches before action is applied to it. internal_logs at 2 writes a report line for every request, including one that scores 0, which is how the first days of traffic become readable. log_tag names this instance in those lines, so give each instance a tag of its own. Setting action to allow until you know how your own traffic scores keeps the instance from refusing a customer; for that window and what it costs, refer to Firewall best practices.
To create the instance:
In Firewalls, select the firewall you created, then select the Functions Instances tab.
A firewall that carries no instance yet offers the same action as + Function Instance.
In the General section, enter a Name. For example: bot-manager-lite.
In the Function section, select the Bot Manager Lite function. The selector holds only the functions in the account that run on a firewall.
In the Arguments section, enter the object. The installed function publishes no argument schema, so the section holds a JSON editor and builds no form from one.
The instance is listed under Functions Instances, with its Name, Function, Last Editor, and Last Modified. The form carries no Active control, because Azion Console creates every instance active.
To change an argument afterwards, select the instance in the same tab, edit the Arguments section, and select Save. A change reaches Azion’s distributed infrastructure in about two minutes, so wait before reading a response as the new configuration. For every argument the object accepts, with its type and its default, refer to Bot Manager Lite.
Create the rule
The instance scores nothing until a rule runs it. A Rules Engine for Firewall rule decides which requests reach the instance, through a Run Function behavior that names it. To create the rule:
In Firewalls, select your firewall, then select the Rules Engine tab.
Enter a name. For example: Run Bot Manager Lite on every request. The description is optional.
In the Criteria section, select the Request Uri variable, the starts with operator, and / as the argument.
In the Behaviors section, select Run Function. The control beside it carries no label and lists the function instances on this firewall, so select the one you named. A rule carries one Run Function behavior.
The firewall runs the instance on every request it receives.
A second criterion narrows that set. Request Uri with the does not match operator keeps the instance off requests that carry nothing to score: static assets, and the /.well-known/ path that automation and web API clients use. For the extensions to exclude and what the exclusion costs, refer to Firewall best practices.
Bind the firewall to the workload
A firewall inspects requests for the workloads bound to it, and the binding sits on the workload’s deployment rather than on the workload record. To bind an existing workload, create a deployment that names both the application and the firewall:
The command prints the id of the new deployment:
Requests to the workload’s domain then reach the firewall, and the rule runs the instance on each one. Give the binding about two minutes before you read anything into a response.
The report line the function writes is where the result of a scored request is. For more information, refer to Logs.