Install the Scheduled Blocking integration
Install Scheduled Blocking from Azion Marketplace and run it on a firewall to control access to your application on a time schedule.
You install the Scheduled Blocking integration from Azion Marketplace and run it on a Firewall, from Azion Console. The integration controls the access to your application based on a time schedule: in the intervals and on the week days you set, it denies, drops, or answers requests with a static response.
Five objects have to exist before a request is blocked: the installed function, a firewall carrying the Functions module, a function instance holding the schedule, a Rules Engine rule with the Run Function behavior, and a workload deployment bound to the firewall. Each section below creates one of them.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload, whose deployment you bind to the firewall in the last section.
- The Azion CLI installed and authorized, for the last section.
- Turning on a product or a module can generate usage costs. For more information, refer to Pricing.
Install the integration
The function is installed once per account. To install it:
Access Azion Console > Marketplace.
Enter Scheduled Blocking in the Search on Marketplace field, then select the integration’s card. Browsing the cards and the categories reaches the same page.
The card shows Successfully installed! and Latest version installed!, and the function appears in the Function list of the Create Instance drawer.
Create the firewall
The firewall is where the function is instanced and where the rule that runs it lives. To create one:
Access Azion Console > Firewalls, then create a firewall.
In the General section, enter a Name. For example: scheduled-blocking-firewall.
In the Modules section, turn on the Functions switch.
The firewall shows a Functions Instances tab while the Functions module stays on. To use an existing firewall instead, turn on its Functions module and save it. For every setting on this form, refer to Set a firewall’s main settings.
Create the function instance
The instance holds the schedule and the action the function takes. To create it:
In Firewalls, select your firewall, then select the Functions Instances tab.
A firewall that has no instance shows the same action as Function Instance. The Create Instance drawer opens.
In Name, enter a name. For example: scheduled-blocking.
In Function, select the Scheduled Blocking function. The list holds only the functions that run on a firewall.
In Arguments, the editor is prefilled with the integration’s default arguments in JSON. Set your schedule, as the next section describes.
The instance is listed in the Functions Instances tab.
Arguments
The arguments are a list of schedule entries. Each entry sets an action, an interval, and the week days it applies to:
| Attribute | Data type | Description |
|---|---|---|
action | String | The action the function runs when a request matches the trigger criteria. Deny closes the request with an HTTP 403 Forbidden response. Drop closes the request without a response to the client. static_response closes the request with a static response. |
execute_action_when | String | in_interval runs the action when the function is called during the time interval. not_in_interval runs the action when the function is called outside the time interval. |
interval | Dictionary of strings | The time interval. The values use the HH:MM format, on a 24-hour clock. The function uses the UTC time zone. |
interval.starts_at_utc | String | The start time of the interval. |
interval.finishes_at_utc | String | The end time of the interval. |
week_days | Dictionary of booleans | The days of the week when the function runs. Each key is a day in a three-letter format (EEE) that starts with a capital letter. The function ignores an invalid day, and reads a day that is not in the dictionary as false. |
static_response_data | Dictionary of strings | The static response page that the function returns when the action is static_response. |
static_response_data.status | Number | The status code of the static response. |
static_response_data.message | String | The custom message on the static response page. |
static_response_data.html | String | The custom HTML that the function delivers as the static response. |
Create the rule
The instance blocks nothing until a rule runs it. A Rules Engine for Firewall rule selects the requests that reach the instance, through a Run Function behavior. To create the rule:
In Firewalls, select your firewall, then select the Rules Engine tab.
In Name, enter a name. For example: Run Scheduled Blocking.
In the Criteria section, select the domains that run the integration. For example: if Host matches yourdomain.com.
In the Behaviors section, select Run Function, then select the instance by the name you gave it.
The firewall runs the instance on every request to the domain in the criterion.
Bind the firewall to the workload
The binding is on the workload’s deployment, so create a deployment that names both the application and the firewall:
The command prints the id of the new deployment:
Requests to the workload’s domain reach the firewall, and the rule runs the Scheduled Blocking instance on each one.