Promotions and product launches: prepare protection around the campaign
Prepare capacity, controlled exceptions and recovery across landing pages, sign-in, stock and callbacks.
Contents of this article
Plan for legitimate peaks and abuse
A launch can attract both real users and abusive traffic. Estimate normal peaks for pages, sign-in, search and transactions, then size mitigation, legitimate bandwidth and origin capacity accordingly.
Validate external dependencies early
Messaging, payment, logistics and callbacks have separate limits and access patterns. Validate domains, certificates, exceptions and retries, and give temporary allow rules a defined scope and review time.
Define degradation for expensive operations
An agreed plan may defer exports or nonessential recommendations to preserve critical transactions. Business owners set priorities, applications maintain idempotency and stock consistency, and mitigation handles the supported network path.
Continue observing after the campaign
After the peak, review queued tasks, duplicate notifications, order state and temporary rules. Use success rates, resource peaks and false positives to plan the next event, retaining only configurations that remain necessary.
References
OWASP Denial of Service Cheat Sheet
