Google Cloud Security, Identity & Compliance
Cloud Armor
DDoS protection and web application firewall for apps behind Google load balancers.
What is Cloud Armor?
Cloud Armor protects applications behind Google's load balancers from DDoS attacks and web exploits, with preconfigured WAF rules, rate limiting and bot management.
Key features
- Preconfigured OWASP WAF rules
- DDoS protection at Google's edge
- Rate limiting
- Adaptive Protection (ML-based)
- Bot management with reCAPTCHA
What it is used for
- Blocking web attacks
- DDoS defence
- Rate limiting and bot control
When to use it
- Public websites and APIs
- Bot and abuse prevention
- Compliance needing a WAF
When something else fits better
- Internal-only services
How pricing works
Standard tier charges per policy, rule and request; Enterprise tier is a subscription with extra protection. Prices change and differ by region; we confirm current costs for your setup before you commit.
Equivalent on AWS
The closest AWS service is AWS WAF: web application firewall that blocks common web attacks and bad bots.
How DomainHostly helps with Cloud Armor
- Plan: choose the right setup, size and region for your workload and budget.
- Set up securely: configure Cloud Armor with least-privilege access, encryption and backups where they apply.
- Migrate: move from shared hosting, your own servers or the other cloud with minimal downtime.
- Run and optimise: monitoring, updates and regular cost reviews so you only pay for what you use.
Security, Identity & Compliance: Identity and access, encryption keys, secrets, firewalls, threat detection and compliance.
What to consider: Security, Identity & Compliance
- Grant the least privilege needed and prefer roles or service accounts over long-lived keys.
- Turn on multi-factor authentication for every administrator account.
- Enable audit logs and threat detection from day one; they are hard to reconstruct after an incident.
Related services: Security, Identity & Compliance
- Identity and Access Management (IAM) (Google Cloud)
- Resource Manager & Organization Policy (Google Cloud)
- Cloud Key Management Service (Google Cloud)
- Secret Manager (Google Cloud)
- Certificate Manager (Google Cloud)
- Security Command Center (Google Cloud)
- AWS IAM (AWS)
- AWS IAM Identity Center (AWS)
- AWS Organizations (AWS)
- AWS KMS (AWS)