You've laid out the core tension well. The "managing rulesets feels heavy" experience with AWS WAF is a critical signal; it's a preview of the hidden operational tax that often gets omitted from vendor comparisons.
Given your specific callouts for API protection and bot mitigation logging, I'd suggest you scrutinize the *observability plane* of each option, not just the control plane. Fastly's compute edge is powerful, but the real question is whether your security team can efficiently trace a block through custom logic, VCL, and managed rules to produce an audit trail. That traceability is often more valuable than the raw capability.
On Radware's cloud WAF, my direct experience is that its strength is in volumetric DDoS mitigation and protocol-level inspections. For the nuanced API and bot logic you seem to need, its tooling felt less iterative compared to vendors built more recently around DevOps workflows. The logging was sufficient for "what," but often lacked the contextual "why" you'd want for tuning.
Avoid getting drawn into a feature checklist. Run a PoC where you feed each vendor a week of real traffic (sanitized, of course) and measure the signal-to-noise ratio in their default bot detection. The vendor whose default rules produce the fewest, most actionable alerts is usually the one whose underlying model aligns best with your application's normal behavior.
Trust but verify.
You mentioned "pricing is opaque" for Fastly, but that's the standard enterprise playbook. The real question is whether their signal sciences offering justifies the inevitable seven-figure commitment when your core need is WAF and DDoS. Their custom logic is powerful until you need to hire a VCL specialist just to tweak a rate limit.
And the F5 hybrid option might seem like a plus until you're paying 30% annual maintenance on a physical box that just routes traffic to their cloud. The on-prem tail wags the cloud dog.
—DW
>bot mitigation that isn't trivial to bypass, and solid logging
Radware is strong on volumetric DDoS, but their API protection and bot logs are a black box. You'll get a "blocked" tag, not the behavioral trace.
Test Fastly's logging during your PoC. Pull an hour of production-like traffic through their test domain and try to build an incident timeline from the raw logs. Their JSON structure is clean, but the real test is their API's rate limits when you're trying to export during an attack.
Avoid AWS WAF if you're already feeling the ruleset weight. The hidden cost is the SRE time to manage priority conflicts and false positives, not the service bill.
Data over opinions
Totally agree on the canary deployment sensitivity to those p99 spikes. We saw something similar during our Fastly trial - their threat intel updates were seamless, but any custom blocklist sync from our own API would cause noticeable latency blips for about 90 seconds. It forced us to schedule those pushes outside our deployment windows.
The setup time vs. incident response trade-off is real. I'd add that the payoff also depends on your team's skills. If you have SREs comfortable with Terraform and writing custom rules, that initial investment in a tool like Reblaze shrinks. If your team is mostly ops-focused and just wants a dashboard to click 'block', that heavy setup feels like a wall.
✌️