---
name: azion-instantiate-a-function-on-a-firewall
description: >-
  Bind a function to a firewall from Azion Console or the Azion API, name the instance, and pass its Args in JSON.
---

# Instantiate a function on a firewall

You can create a function instance on a firewall from Azion Console or the Azion API. The instance binds one function to one firewall and carries the Args passed into the execution context.

An instance without a Rules Engine rule never runs. The rule selects the instance with the **Run Function** behavior and sets the criteria that trigger it. To create the function, turn on the module, instantiate it, and add the rule in one pass, refer to [Run a function on a firewall](/en/documentation/guides/application-development/functions-and-runtime/firewall/).

To create the same object on an application, refer to [Instantiate a function on an application](/en/documentation/guides/application-development/getting-started/instantiate-functions/).

---

## Prerequisites

- A firewall with the **Functions** module turned on. To turn on the module, refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).
- A function whose **Initiator Type** is *Firewall*. Take one from [Azion Marketplace](/en/documentation/platform/marketplace/), or write one, as in the [Deny a request by country](/en/documentation/platform/functions/deny-request/) example.
- A [personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/), for the API path.

> **Caution**
>
> Computing time and invocations for functions generate usage-related costs. For the rates, refer to [Pricing](/en/documentation/fundamentals/pricing/).

---

## Create the function instance

A firewall runs a function through an instance, and one function can serve several instances. The **Functions Instances** tab appears only when the **Functions** module is on. To create the instance:

**Console**

To create the instance from Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewall** > **your firewall**.

2. **Go to the Functions Instances tab**

3. **Select + Function Instance**

4. **Name the instance**

   Enter a name for the instance. For example: `deny-request instance`.

5. **Select the function**

   In the **Functions** field, select the function the instance runs. Only functions whose **Initiator Type** is set to *Firewall* appear in the list.

6. **Enter the Args**

   (Optional) In the **Args** tab, enter the arguments for the instance in JSON.

7. **Select Save**

The instance appears in the **Functions Instances** tab. It does not run until a Rules Engine rule selects it.

**API**

To create the instance with the Azion API:

1. **Read the ID of the function**

   Send a `GET` request to the functions endpoint, replacing `[TOKEN VALUE]` with your personal token:

   ```bash
   curl --request GET \
     --url https://api.azion.com/v4/workspace/functions \
     --header 'Accept: application/json' \
     --header 'Authorization: Token [TOKEN VALUE]'
   ```

   The response lists the functions on the account. Copy the `id` of a function whose `initiator_type` is `edge_firewall`:

   ```json
   {
     "count": 1,
     "results": [
       {
         "id": 13426,
         "name": "deny-request",
         "language": "javascript",
         "initiator_type": "edge_firewall",
         "active": true,
         "reference_count": 1
       }
     ]
   }
   ```

2. **Create the instance on the firewall**

   Send a `POST` request to the firewall functions endpoint, replacing `<edge_firewall_id>` with the ID of the firewall and `<function_id>` with the ID you copied:

   ```bash
   curl --request POST \
     --url https://api.azion.com/v4/workspace/firewalls/<edge_firewall_id>/functions \
     --header 'Accept: application/json' \
     --header 'Authorization: Token [TOKEN VALUE]' \
     --header 'Content-Type: application/json' \
     --data '{
     "name": "deny-request instance",
     "args": {},
     "function": <function_id>,
     "active": true
   }'
   ```

   The response returns the instance that the firewall now carries:

   ```json
   {
     "results": {
       "id": 2806,
       "name": "deny-request instance",
       "json_args": {},
       "function": 13426,
       "last_editor": "your-email@example.com",
       "last_modified": "2023-11-22T18:50:11.812819Z"
     },
     "schema_version": 3
   }
   ```

The instance exists on the firewall, and the response carries its fields:

| Key         | Description                                                                                       |
| ----------- | ------------------------------------------------------------------------------------------------- |
| `id`        | The ID of the function instance                                                                   |
| `name`      | The name of the function instance                                                                 |
| `function`  | The ID of the function the instance runs. It differs from `id`, which is unique for each instance |
| `json_args` | The arguments passed into the execution context of the function. Some functions take no arguments |

It does not run until a Rules Engine rule selects it. Changes take a few minutes to propagate.

> **Note**
>
> To retrieve the ID of a firewall, send a `GET` request to `https://api.azion.com/v4/workspace/firewalls`. For the request and its response, refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).

> **Tip**
>
> For every endpoint and its fields, refer to the [Azion API documentation](https://api.azion.com/) and the [OpenAPI specification](https://github.com/aziontech/azionapi-openapi/).

---

## Instance Args

Args is a JSON object passed into the execution context of the function. The source code of a function cannot be changed from the instance, so Args is how one function serves several firewalls with different configurations. An Args object that sets two keys:

```json
{
  "threshold": 50,
  "action": "block"
}
```

A function carries default arguments, set on the function itself. The instance overrides the keys it declares and inherits the rest. An instance accepts a maximum of 100 KB of arguments.

For the default values and the override rules, refer to [How Functions works](/en/documentation/platform/functions/how-it-works/). For the configuration samples and the other limits, refer to [Functions Instances for Firewall](/en/documentation/platform/firewall/functions-instances/).

---

## Next steps

- [Run a function on a firewall](/en/documentation/guides/application-development/functions-and-runtime/firewall.md): Create the function, turn on the module, and add the Rules Engine rule that triggers the instance.
- [Create rules in Rules Engine for Firewall](/en/documentation/guides/application-security/firewall-and-waf/work-with-rules-engine.md): The rule that selects the instance, from Azion Console or the Azion API.
- [Functions Instances for Firewall](/en/documentation/platform/firewall/functions-instances.md): The argument hierarchy, the configuration samples, and the limits an instance runs inside.
- [Instantiate a function on an application](/en/documentation/guides/application-development/getting-started/instantiate-functions.md): The same object on an application, where the rule also sets the execution phase.
