NGINX Ingress Controller (based on NGINX Plus) combines the speed and performance of NGINX with the trust and security behind the power of F5. Protecting your Kubernetes applications is easy using NGINX App Protect DoS, a lightweight, modern application and API, software security solution that seamlessly integrates security policies into DevOps environments to enable "security as code" as a layer 7 Denial of Service (DoS) defense. Designed to defend traditional HTTP/HTTPS and modern HTTP2 applications, like gRPC and WebSocket, against sophisticated DoS/DDoS attacks. NGINX App Protect DoS runs natively on NGINX Ingress Controller on all platforms, architectures and AWS hybrid environments while delivering consistent performance and protection across your entire infrastructure. NGINX Ingress Controller is high-performing, production-ready, and suitable for long-term deployment. We focus on providing stability across releases, with features that can be deployed at enterprise scale.
NGINX Ingress Controller is a best-in-class traffic management solution for cloud-native apps in Kubernetes and containerized environments in Amazon EKS. Get your free 30-day trial today!
In a CNCF survey, two-thirds of respondents reported using the NGINX Ingress Controller (more than all other controllers combined) and NGINX Ingress Controller has been downloaded more than 10 million times on DockerHub. Combining the speed and performance of NGINX with the trust and security behind the power of F5, NGINX Ingress Controller is synonymous with high-performing, scalable, and secure modern apps in production.
This is the official implementation of NGINX Ingress Controller (based on NGINX Plus) from NGINX. It is high-performance, production-ready, and suitable for long-term deployment. We focus on providing stability across releases, with features that can be deployed at enterprise scale. Included in this subscription is NGINX's award-winning support.
Protecting your Kubernetes applications is easy using NGINX App Protect DoS, a lightweight, modern application and API, software security solution that seamlessly integrates security policies into DevOps environments to enable "security as code" as a layer 7 Denial of Service (DoS) defense. NGINX App Protect DoS runs natively on NGINX Ingress Controller on all platforms, architectures and AWS hybrid environments while delivering consistent performance and protection across your entire infrastructure. It can be deployed in various Kubernetes environment locations to protect your cloud-native apps which includes being embedded within the NGINX Ingress Controller, or within the cluster at the pod level as a per-service proxy or as a per-pod proxy delivering reduced complexity, TCO, manual oversight and tool sprawl. It can provide detailed observability and insights via security log integration with external SIEM tools. NGINX App Protect DoS enables scalable DoS/DDoS protection for web applications, microservices, cloud-native apps, and APIs to deliver strong security, high-performance and low latency across your AWS EKS environments.
NGINX App Protect Denial of Service (DoS) is a dynamic software security module that mitigates app and API DoS/DDoS attacks at layer 7. NGINX App Protect DoS is easy to implement, requiring minimal setup and configuration to get started, and can also be used as a standalone security solution and operate without the installation of NGINX App Protect WAF. Designed to defend traditional HTTP/HTTPS and modern HTTP2 applications, like gRPC and WebSocket, against even the most sophisticated DoS/DDoS attacks that include GET and POST flood attacks, Slowloris, Slow read, Slow POST, NAT evasion attacks and targeted SSL/TLS attacks.
NGINX App Protect DoS establishes a baseline for normal traffic patterns using a machine learning based algorithm and analysis of over 320 metrics related to client behavior and application/API health, to significantly reduce false positives. It constructs and deploys dynamic signatures to mitigate attacks automatically, then continuously measures mitigation effectiveness and adapts to changing behavior or health conditions. Attack details are shared among multiple NGINX Ingress Controller instances to help mitigate potential future attacks even if only one instance was attacked. NGINX App Protect DoS adaptive learning allows for no-touch policy configuration and delivers consistent DoS/DDoS protection to ensure zero-day protection. NGINX App Protect DoS provides a configurable, robust, multi-layered defense, to deliver the best strategy to mitigate attacks per individual application which includes: 1.) mitigating volumetric attacks, 2.) adaptive learning to detect anomalies and consistently mitigate attacks and 3.) to apply global rate limiting as needed.
NGINX App Protect DoS security solution helps SecOps and DevOps teams work together in migrating towards a shift left or DevSecOps strategy by facilitating "security as code" for consistent app security automation. This lightweight software package provides a continuous feedback loop for threat mitigation effectiveness, enabling developer agility and empowering organizations to bring applications to market at speed without compromising on security.
Highlights
NGINX Ingress Controller delivers advanced app-centric configuration: Use role-based access control and self-service to set up security guardrails, so your teams can manage their apps securely and with agility. Enable multi-tenancy, reusability, simpler configs, and more.
NGINX App Protect DoS establishes a baseline for normal traffic patterns using a machine learning based algorithm and analysis of over 320 metrics related to client behavior and application/API health, to greatly reduce false positives. It constructs and deploys dynamic signatures to mitigate attacks automatically. NGINX App Protect DoS adaptive learning allows for no-touch policy configuration and delivers consistent DoS protection to ensure zero-day protection for a multi-layered defense.
NGINX Ingress Controller provides visibility and performance monitoring: Pinpoint undesirable behaviors and performance bottlenecks to simplify troubleshooting and make fixes faster.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Try this product free for 30 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.
F5 NGINX Ingress Controller with F5 NGINX App Protect DoS
You pay by the hour for each running container, billed on usage. There is one pricing dimension: Container Hours. Your cost scales with how many containers you run and how long they run. No upfront commitment or fixed term applies. As you add or remove containers, or scale pods up and down, your billed hours rise or fall accordingly. This usage-based model ties spending directly to your deployed footprint across Kubernetes environments, letting you match costs to actual runtime rather than a set quantity.
Top-of-mind questions for buyers
What counts as one billed Container Hour for this product?
You are billed per hour for each running container that hosts the Ingress Controller with App Protect DoS. Each container instance meters its own runtime separately. Multiple containers running at the same time each accrue hours. Partial-hour billing follows AWS metering rules for the running time of each container.
Am I charged when containers are scaled down or stopped?
Charges accrue only while containers run. When you scale pods down or stop containers, those containers stop adding Container Hours. As Kubernetes scales your deployment back up, hours resume for the new running containers. Your billed hours track the live footprint, not a fixed count.
What deployment environments can I run these containers in?
The Ingress Controller runs inside Kubernetes, translating ingress resources into NGINX configurations for routing, load balancing, and security. The App Protect DoS component deploys natively on the Ingress Controller or as a per-pod or per-service proxy. It supports on-premises, hybrid, and multi-cloud clusters. Billing stays per Container Hour regardless of environment.
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.