Notifications
Clear all
Topic starter
20/07/2026 7:26 am
Just tried to set up rate limiting on our API with AWS WAF. It's powerful, but the defaults can be tricky! What rules are you all running in production?
I'm currently using:
- **Rate-based rules** on the IP address for login endpoints.
- **Separate rules** for different URI paths (API vs. assets).
- **Low threshold for /admin paths**.
Biggest lesson so far: combine it with AWS Shield Advanced for DDoS protection on the same endpoints. The combo is solid.
What's your go-to setup? Any pitfalls with the aggregation keys or latency?
Let's build better workflows.