Skip to main content

Before you begin

You need an active Cloud Shield plan, a Cloud CDN distribution in the selected project, and permission to create protected resources. Configure the distribution’s origin, hostname, and TLS before adding protection.
1

Select the project

Select the organization and project that own the application. Open Cloud Shield → Protected domains.
2

Choose a distribution

Select Protect a CDN distribution, choose an available distribution, and confirm. Cloud Shield uses the distribution’s existing connection; it does not require a separate origin or a new DNS target.
3

Wait for setup

Refresh the protected domains list until setup completes. A pending attachment may appear before a protected-domain identifier is assigned. Review the linked distribution if setup remains pending.
4

Review protection

Open the domain’s Managed protection and Protection settings. Review enabled policies and choose the protection mode appropriate to your rollout. Monitor mode lets you inspect detections before enforcing protection.
5

Verify real traffic

Request your application through its CDN hostname. Check application responses, then inspect Traffic analytics and Security events. Analytics can lag traffic; check the displayed data freshness before interpreting an empty result.

Attach through the API

Use a distribution ID returned by GET /shield/distributions for the same project. The response includes distribution_id, name, status, and an id that can be null while setup is pending. Read the resource again before applying domain-specific settings.

Remove protection

Use Protection settings → Detach Cloud Shield for an initialized domain. For a pending attachment, use Detach pending protection in the distribution setup view. Detaching stops application protection while the CDN distribution continues delivering traffic. It does not cancel the organization’s Cloud Shield subscription. Next, tune policies and rules and review security events.