> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Protect your first application

> Attach Cloud Shield to a Cloud CDN distribution, verify readiness, and review protected traffic.

## Before you begin

You need an active Cloud Shield plan, a Cloud CDN distribution in the selected project, and permission to create protected resources. Configure the distribution's origin, hostname, and TLS before adding protection.

<Steps>
  <Step title="Select the project">
    Select the organization and project that own the application. Open **Cloud Shield → Protected domains**.
  </Step>

  <Step title="Choose a distribution">
    Select **Protect a CDN distribution**, choose an available distribution, and confirm. Cloud Shield uses the distribution's existing connection; it does not require a separate origin or a new DNS target.
  </Step>

  <Step title="Wait for setup">
    Refresh the protected domains list until setup completes. A pending attachment may appear before a protected-domain identifier is assigned. Review the linked distribution if setup remains pending.
  </Step>

  <Step title="Review protection">
    Open the domain's **Managed protection** and **Protection settings**. Review enabled policies and choose the protection mode appropriate to your rollout. Monitor mode lets you inspect detections before enforcing protection.
  </Step>

  <Step title="Verify real traffic">
    Request your application through its CDN hostname. Check application responses, then inspect **Traffic analytics** and **Security events**. Analytics can lag traffic; check the displayed data freshness before interpreting an empty result.
  </Step>
</Steps>

## Attach through the API

```bash theme={null}
curl --request POST \
  --url https://api.aptranet.com/shield/domains \
  --header "Authorization: Bearer $APTRANET_ACCESS_KEY" \
  --header "Aptranet-Secret: $APTRANET_SECRET" \
  --header "Content-Type: application/json" \
  --data '{"distribution_id": 42}'
```

Use a distribution ID returned by `GET /shield/distributions` for the same project. The response includes `distribution_id`, `name`, `status`, and an `id` that can be null while setup is pending. Read the resource again before applying domain-specific settings.

## Remove protection

Use **Protection settings → Detach Cloud Shield** for an initialized domain. For a pending attachment, use **Detach pending protection** in the distribution setup view. Detaching stops application protection while the CDN distribution continues delivering traffic. It does not cancel the organization's Cloud Shield subscription.

Next, [tune policies and rules](/cloud-shield/policies-and-rules) and [review security events](/cloud-shield/investigations).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.