---
title: Charmhub | Deploy HAProxy using Charmhub - The Open Operator Collection
description: Deploy the latest version of HAProxy on any cloud.
url: https://charmhub.io/haproxy/libraries/ddos_protection
---

# HAProxy

[haproxy-team](https://charmhub.io/publisher/haproxy-team "View all packages from haproxy-team")

* [haproxy-team](https://charmhub.io/publisher/haproxy-team "View all packages from haproxy-team")
* [Networking](https://charmhub.io/?filter=networking)

Platform:

24.04

22.04

20.04

18.04

16.04

14.04

stable 147

```
juju deploy haproxy
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/haproxy/libraries/ddos_protection#drawer)

## charms.haproxy.v0.ddos\_protection

* [*Docstrings*Docstrings](https://charmhub.io/haproxy/libraries/ddos_protection)
  [*Code*Source code](https://charmhub.io/haproxy/libraries/ddos_protection/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.haproxy.v0.ddos_protection
    ```

    [Download ddos\_protection.py](https://charmhub.io/haproxy/libraries/ddos_protection/download)
  + *Last updated* 11 Sep 2026
  + *Revision* Library version 0.4

DDoS protection interface library.

##### Getting Started

To get started using the library, you need to first declare the library in
the charm-libs section of your `charmcraft.yaml` file:

```
charm-libs:
- lib: haproxy.ddos_protection
  version: "0"
```

Then, fetch the library using `charmcraft`:

```
cd some-charm
charmcraft fetch-libs
```

##### Using the library as the Provider

The provider charm should expose the interface as shown below:

```
provides:
    ddos-protection:
        interface: ddos-protection
```

Then, to initialise the library:

```
from charms.haproxy.v0.ddos_protection import DDoSProtectionProvider

class DDoSConfigurator(CharmBase):
    def __init__(self, *args):
        super().__init__(*args)
        self.ddos_provider = DDoSProtectionProvider(self)
        # Set the configuration when ready
        self.ddos_provider.set_config(
            rate_limit_requests_per_minute=100,
            rate_limit_connections_per_minute=50,
            concurrent_connections_limit=1000,
            error_rate=10,
            limit_policy_http="reject",
            limit_policy_tcp="reject",
            ip_allow_list=["192.168.1.1", "192.168.1.0/24"],
            http_request_timeout=30,
            http_keepalive_timeout=60,
            client_timeout=50,
            deny_paths=["/admin", "/internal"],
        )
```

##### Using the library as the Requirer

The requirer charm should expose the interface as shown below:

```
requires:
    ddos-protection:
        interface: ddos-protection
```

Then, to initialise the library:

```
from charms.haproxy.v0.ddos_protection import DDoSProtectionRequirer

class HaproxyCharm(CharmBase):
    def __init__(self, *args):
        super().__init__(*args)
        self.ddos_requirer = DDoSProtectionRequirer(self, relation_name="ddos-protection")

        self.framework.observe(
            self.on.config_changed, self._on_config_changed
        )

    def _on_config_changed(self, event):
        # Read DDoS protection configuration
        config = self.ddos_requirer.get_ddos_config()
        if config:
            # Apply the configuration
            ...
```

---

Index

* [class DataValidationError](https://charmhub.io/haproxy/libraries/ddos_protection#datavalidationerror)
* [class DDoSProtectionInvalidRelationDataError](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectioninvalidrelationdataerror)
* [class HttpRateLimitPolicy](https://charmhub.io/haproxy/libraries/ddos_protection#httpratelimitpolicy)
* [class TcpRateLimitPolicy](https://charmhub.io/haproxy/libraries/ddos_protection#tcpratelimitpolicy)
* [class DDoSProtectionProviderAppData](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionproviderappdata)
* + [def validate\_ip\_allow\_list(
    cls,
    v)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionproviderappdata-validate_ip_allow_list)
* + [def validate\_deny\_paths(
    cls,
    v)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionproviderappdata-validate_deny_paths)
* + [def validate\_limit\_policies(
    self)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionproviderappdata-validate_limit_policies)
* + [def validate\_limit\_policies\_with\_rate\_limits(
    self)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionproviderappdata-validate_limit_policies_with_rate_limits)
* [class DDoSProtectionProvider](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionprovider)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionprovider-__init__)
* + [def set\_config(
    self)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionprovider-set_config)
* [class DDoSProtectionRequirer](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionrequirer)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionrequirer-__init__)
* + [def get\_ddos\_config(
    self)](https://charmhub.io/haproxy/libraries/ddos_protection#ddosprotectionrequirer-get_ddos_config)

#### class DataValidationError

Description

Raised when data validation fails. None

#### class DDoSProtectionInvalidRelationDataError

Description

Raised when data validation of the ddos-protection relation fails. None

#### class HttpRateLimitPolicy

Enum of possible HTTP rate limiting policies.

Description

Attrs:
DENY: Deny the connection.
REJECT: Send a TCP reset packet to close the connection.
SILENT: disconnects immediately without notifying the client
that the connection has been closed (no packet sent).

#### class TcpRateLimitPolicy

Enum of possible TCP rate limiting policies.

Description

Attrs:
REJECT: Send a TCP reset packet to close the connection.
SILENT: disconnects immediately without notifying the client
that the connection has been closed (no packet sent).

#### class DDoSProtectionProviderAppData

Configuration model for DDoS protection provider.

Attributes

rate\_limit\_requests\_per\_minute

Maximum number of requests per minute per entry.

rate\_limit\_connections\_per\_minute

Maximum number of connections per minute per entry.

concurrent\_connections\_limit

Maximum number of concurrent connections per entry.

error\_rate

Number of errors per minute per entry to trigger the limit policy.

limit\_policy\_http

Policy to be applied when HTTP-level limits are exceeded.

limit\_policy\_tcp

Policy to be applied when TCP-level limits are exceeded.

policy\_status\_code

HTTP status code for deny policy (only set when limit\_policy\_http is deny).

ip\_allow\_list

List of IPv4 addresses or CIDR blocks to be allowed.

http\_request\_timeout

Timeout for HTTP requests in seconds.

http\_keepalive\_timeout

Timeout for HTTP keep-alive connections in seconds.

client\_timeout

Timeout for client connections in seconds.

deny\_paths

List of paths to deny.

Methods

DDoSProtectionProviderAppData.
validate\_ip\_allow\_list(

cls

,
v
)

Validate and convert IP allow list.

Arguments

v

The list of IP addresses or CIDR blocks as strings.

Returns

The list of converted IPv4Address or IPv4Network objects.

Description

Converts each string to either IPv4Address (for single IPs) or IPv4Network (for CIDR blocks).

DDoSProtectionProviderAppData.
validate\_deny\_paths(

cls

,
v
)

Validate that deny\_paths contains no empty strings.

Arguments

v

The validated list of paths.

Returns

The validated list of paths.

DDoSProtectionProviderAppData.
validate\_limit\_policies(

*self*
)

Validate and convert the limit\_policy\_http and limit\_policy\_tcp parameters.

Returns

The validated model.

Description

The limit\_policy\_http must be one of: silent-drop, reject, or deny.
The limit\_policy\_tcp must be one of: silent-drop or reject.
For deny, optionally an HTTP status code can be appended (e.g., "deny 503").
Extracts and stores the status code separately in policy\_status\_code.

DDoSProtectionProviderAppData.
validate\_limit\_policies\_with\_rate\_limits(

*self*
)

Validate that limit policies are only set when corresponding rate limits are configured.

Returns

The validated model.

Description

HTTP policy applies to: rate\_limit\_requests\_per\_minute, error\_rate
TCP policy applies to: rate\_limit\_connections\_per\_minute, concurrent\_connections\_limit
Sets default policies to SILENT when rate limits are present but policies are not set.

#### class DDoSProtectionProvider

Description

DDoS protection interface provider implementation. None

Methods

DDoSProtectionProvider.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

Initialize the DDoSProtectionProvider.

Arguments

charm

The charm that is instantiating the library.

relation\_name

The name of the relation.

DDoSProtectionProvider.
set\_config(

*self*
)

Update the DDoS protection configuration.

Arguments

rate\_limit\_requests\_per\_minute

Maximum number of requests per minute per entry.

rate\_limit\_connections\_per\_minute

Maximum number of connections per minute per entry.

concurrent\_connections\_limit

Maximum number of concurrent connections per entry.

error\_rate

Number of errors per minute per entry to trigger the limit policy.

limit\_policy\_http

Policy to be applied when HTTP-level limits are exceeded.

limit\_policy\_tcp

Policy to be applied when TCP-level limits are exceeded.

ip\_allow\_list

List of IPv4 addresses or CIDR blocks to be allowed.

http\_request\_timeout

Timeout for HTTP requests in seconds.

http\_keepalive\_timeout

Timeout for HTTP keep-alive connections in seconds.

client\_timeout

Timeout for client connections in seconds.

deny\_paths

List of paths to deny.

#### class DDoSProtectionRequirer

Description

DDoS protection interface requirer implementation. None

Methods

DDoSProtectionRequirer.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

Initialize the DDoSProtectionRequirer.

Arguments

charm

The charm that is instantiating the library.

relation\_name

The name of the relation to bind to.

DDoSProtectionRequirer.
get\_ddos\_config(

*self*
)

Retrieve the DDoS protection configuration from the provider.

Returns

DDoSProtectionProviderAppData

The DDoS protection configuration if available,
or None if the relation is not established or contains no data.
