Run Bot Manager on every request
Create the Rules Engine rule that hands every request a firewall receives to one Bot Manager instance, from Azion Console, the Azion CLI, or the API.
You can run a Bot Manager instance on every request a firewall receives with one Rules Engine for Firewall rule, from Azion Console, the Azion CLI, or the API. A function instance scores nothing until a rule hands it a request; for where the rule sits in the path a request travels, refer to Bot scoring.
Prerequisites
- A firewall bound to the workload that serves your application. Refer to the Bot Manager quickstart.
- A Bot Manager function instance on that firewall, and its id. To create one, refer to Run Bot Manager in observation mode.
- The Azion CLI installed and a configured personal token, for the CLI procedure.
- A personal token, for the API procedure. To create one, refer to Personal Tokens.
Create the rule
The rule below matches every request its firewall receives and runs one instance on each of them. value holds the id of the function instance on this firewall, so replace 12347 with your own. It never holds the id of the installed function, which is the same for every instance of it in the account.
To create the rule from Azion Console:
Access Azion Console > Firewalls, then select that firewall.
Enter Run Bot Manager on every request as the name. The description is optional.
In the Criteria section, select Request Uri as the variable and starts with as the operator, then enter / as the argument.
In the Behaviors section, select Run Function. Doing so adds a second control, which carries no label and the placeholder Select an function. That control holds the function instances on this firewall; select the one to run.
The firewall now holds the rule, and the instance scores every request the firewall receives. The behavior selector lists instances, not functions, and only the active ones. A rule carries at most one Run Function behavior, which Azion Console enforces by disabling the option once one is in the rule. The Request Uri variable needs nothing else turned on, while Header User Agent and Request Args are offered only while WAF is on for the firewall.