Instantiate a function on a firewall
Bind a function to a firewall from Azion Console or the Azion API, name the instance, and pass its Args in JSON.
You can create a function instance on a firewall from Azion Console or the Azion API. The instance binds one function to one firewall and carries the Args passed into the execution context.
An instance without a Rules Engine rule never runs. The rule selects the instance with the Run Function behavior and sets the criteria that trigger it. To create the function, turn on the module, instantiate it, and add the rule in one pass, refer to Run a function on a firewall.
To create the same object on an application, refer to Instantiate a function on an application.
Prerequisites
- A firewall with the Functions module turned on. To turn on the module, refer to Set a firewall’s main settings.
- A function whose Initiator Type is Firewall. Take one from Azion Marketplace, or write one, as in the Deny a request by country example.
- A personal token, for the API path.
Create the function instance
A firewall runs a function through an instance, and one function can serve several instances. The Functions Instances tab appears only when the Functions module is on. To create the instance:
To create the instance from Azion Console:
Access Azion Console > Firewall > your firewall.
Enter a name for the instance. For example: deny-request instance.
In the Functions field, select the function the instance runs. Only functions whose Initiator Type is set to Firewall appear in the list.
(Optional) In the Args tab, enter the arguments for the instance in JSON.
The instance appears in the Functions Instances tab. It does not run until a Rules Engine rule selects it.
Instance Args
Args is a JSON object passed into the execution context of the function. The source code of a function cannot be changed from the instance, so Args is how one function serves several firewalls with different configurations. An Args object that sets two keys:
A function carries default arguments, set on the function itself. The instance overrides the keys it declares and inherits the rest. An instance accepts a maximum of 100 KB of arguments.
For the default values and the override rules, refer to How Functions works. For the configuration samples and the other limits, refer to Functions Instances for Firewall.