# Shield

Source: /aws/services/shield/

## Introduction

Shield is a managed Distributed Denial of Service (DDoS) protection service that safeguards applications running on AWS.
Shield provides always-on detection and inline mitigations that minimize application downtime and latency, by protecting users from L4, L7 and most common L3, L4 network and transport layer DDoS attacks.
Shield detection and mitigation is designed to protect against threats, including ones that are not known to the service at the time of detection.

LocalStack allows you to use the Shield APIs in your local environment, and provides a simple way to mock and test the Shield service locally.
The supported APIs are available on our [API Coverage section](#api-coverage), which provides information on the extent of Shield's integration with LocalStack.

## Getting Started

This guide is designed for users new to Shield and assumes basic knowledge of the AWS CLI and our [`lstk aws`](/aws/developer-tools/running-localstack/lstk/cloud-and-iac-commands/#aws) command.

Start your LocalStack container using your preferred method.
We will demonstrate how to create a Shield protection, list all protections, and delete a protection with the AWS CLI.

### Create a Shield Protection

To create a Shield protection, use the [`CreateProtection`](https://docs.aws.amazon.com/cli/latest/reference/shield/create-protection.html) API.
The following command creates a Shield protection for a resource:

```bash
lstk aws shield create-protection \
  --name "my-protection" \
  --resource-arn "arn:aws:elasticloadbalancing:us-east-1:000000000000:loadbalancer/app/my-alb/1234567890"
```

```bash title="Output"
{
    "ProtectionId": "67908d33-16c0-443d-820a-31c02c4d5976"
}
```

### List all Protections

To list all Shield protections, use the [`ListProtections`](https://docs.aws.amazon.com/cli/latest/reference/shield/list-protections.html) API.
The following command lists all Shield protections:

```bash
lstk aws shield list-protections
```

```bash title="Output"
{
    "Protections": [
        {
            "Id": "67908d33-16c0-443d-820a-31c02c4d5976",
            "Name": "my-protection",
            "ResourceArn": "arn:aws:elasticloadbalancing:us-east-1:000000000000:loadbalancer/app/my-alb/1234567890",
            "ProtectionArn": "arn:aws:shield::000000000000:protection/67908d33-16c0-443d-820a-31c02c4d5976"
        }
    ]
}
```

### Describe a Protection

To describe a Shield protection, use the [`DescribeProtection`](https://docs.aws.amazon.com/cli/latest/reference/shield/describe-protection.html) API.
The following command describes a Shield protection:

```bash
lstk aws shield describe-protection \
  --protection-id "67908d33-16c0-443d-820a-31c02c4d5976"
```

Replace the protection ID with the ID of the protection you want to describe.

```bash title="Output"
{
    "Protection": {
        "Id": "67908d33-16c0-443d-820a-31c02c4d5976",
        "Name": "my-protection",
        "ResourceArn": "arn:aws:elasticloadbalancing:us-east-1:000000000000:loadbalancer/app/my-alb/1234567890",
        "ProtectionArn": "arn:aws:shield::000000000000:protection/67908d33-16c0-443d-820a-31c02c4d5976"
    }
}
```

### Delete a Protection

To delete a Shield protection, use the [`DeleteProtection`](https://docs.aws.amazon.com/cli/latest/reference/shield/delete-protection.html) API.
The following command deletes a Shield protection:

```bash
lstk aws shield delete-protection \
  --protection-id "67908d33-16c0-443d-820a-31c02c4d5976"
```

## Current Limitations

Shield Config is currently mocked in LocalStack.
You can create, read, update, and delete Shield protections & subscriptions, but the actual protection or subscription is not applied to any resources.
If you need this feature, please consider opening a [feature request on GitHub Discussion](https://github.com/orgs/localstack/discussions/new/choose).

## API Coverage


### shield API coverage

Source service: `shield`. 12 of 36 tracked operations are implemented.

Service documentation: /aws/services/shield/
License availability: available starting with the Ultimate plan. See /aws/licensing/ for current plan details.

| Operation | Status |
| --- | --- |
| AssociateDRTLogBucket | Not implemented |
| AssociateDRTRole | Not implemented |
| AssociateHealthCheck | Not implemented |
| AssociateProactiveEngagementDetails | Not implemented |
| CreateProtection | Implemented |
| CreateProtectionGroup | Not implemented |
| CreateSubscription | Implemented |
| DeleteProtection | Implemented |
| DeleteProtectionGroup | Not implemented |
| DeleteSubscription | Not implemented |
| DescribeAttack | Not implemented |
| DescribeAttackStatistics | Not implemented |
| DescribeDRTAccess | Not implemented |
| DescribeEmergencyContactSettings | Not implemented |
| DescribeProtection | Implemented |
| DescribeProtectionGroup | Not implemented |
| DescribeSubscription | Implemented |
| DisableApplicationLayerAutomaticResponse | Implemented |
| DisableProactiveEngagement | Not implemented |
| DisassociateDRTLogBucket | Not implemented |
| DisassociateDRTRole | Not implemented |
| DisassociateHealthCheck | Not implemented |
| EnableApplicationLayerAutomaticResponse | Implemented |
| EnableProactiveEngagement | Not implemented |
| GetSubscriptionState | Not implemented |
| ListAttacks | Not implemented |
| ListProtectionGroups | Not implemented |
| ListProtections | Implemented |
| ListResourcesInProtectionGroup | Not implemented |
| ListTagsForResource | Implemented |
| TagResource | Implemented |
| UntagResource | Implemented |
| UpdateApplicationLayerAutomaticResponse | Implemented |
| UpdateEmergencyContactSettings | Not implemented |
| UpdateProtectionGroup | Not implemented |
| UpdateSubscription | Not implemented |
