Skip to main content
Cloud Shield adds application protection to an existing Cloud CDN distribution. Protected domains, rules, investigations, and access controls belong to the selected project. Your organization’s plan and add-ons determine which controls are available.

Protect an application

Attach a distribution and verify protection.

Manage protection

Configure managed policies, exceptions, and traffic rules.

Investigate traffic

Review events, attack activity, IP reputation, and insights.

Operate your workspace

Manage response pages, access, audit events, usage, and exports.

Product boundaries

Cloud Shield and Origin Shield are separate features with separate configuration and billing.

Plans and entitlements

The service reports your current limits through GET /shield/service. Domain and rule limits apply across the organization’s projects. Basic supports managed protection; Advanced and Business also support custom and IP firewall rules. Advanced rules and bot management require eligible add-ons. API security, advanced threat intelligence, SIEM integration, access control, and audit logs require their corresponding Business add-ons. Review the current plan and available controls in Billing → Subscription. A visible navigation item does not mean its add-on is active. Contact support to enable an eligible add-on.

Automation

The public API prefix is /shield; the Management Console uses /cloud-shield for its pages. Use project-scoped credentials and the Cloud Shield API guide when automating protection.