Aman Dhesi
@aman
Devcasters, what's the simplest and cheapest way to protect an AWS Fargate-hosted public API server from DDoS attacks? Is the basic AWS shield enough or would you recommend setting up AWS web application firewall?
2 replies
0 recast
0 reaction
Shane da Silva
@sds
If trying to remain on AWS for all infra, Shield will be your only option, but the pricing ain't cheap. If willing to delegate your DNS to Cloudflare, you can get pretty awesome (IMO) built-in DDoS protection for free, and optional analytics for $25/mth on their Business plan.
1 reply
0 recast
0 reaction
Aman Dhesi
@aman
Awesome, ty! ❤️
1 reply
0 recast
0 reaction
Shane da Silva
@sds
Sorry, I should have been more explicit: if willing to delegate your DNS to [and proxy all traffic via] Cloudflare is what you need if you want Cloudflare's DDoS protection to work. That may add some latency depending on your your use case.
1 reply
0 recast
0 reaction
Aman Dhesi
@aman
Do you think cloudfront's free ddos protection is significantly better than well-configured AWS WAF (which is much cheaper than Shield Advanced)? https://aws.amazon.com/waf/
2 replies
0 recast
0 reaction