86. Design an IP and URL Denylist
Deny requests by caller address, range or URL at a global edge, with lists from governments, threat feeds and detection reaching 300 proxies in seconds.
The brief
Design an IP and URL Denylist. Deny requests by caller address, range or URL at a global edge, with lists from governments, threat feeds and detection reaching 300 proxies in seconds. Work from the scoping questions below. State assumptions for any unspecified load, guarantee or target, then trace your design end to end. Explain one difficult case and a credible alternative; the worked example is a reference, not a required implementation.
- Set the scope: Block what, where? How big?
- Define the contract: How fast must a change land? Whose law?
- Test the boundaries: Our own detection? A source that answers one address at a time? Only deny?
Constraints
- Explicit scope and guarantees
- Resolve the scoping questions for an IP and URL Denylist. Separate stated behavior from assumptions, and identify what is outside your design.
- Supported operating targets
- Declare relevant volume, latency, freshness, quality or cost targets with units. Show calculations or an evaluation plan that can test them; unspecified targets are your assumptions, not hidden pass criteria.
- Failure and boundary behavior
- Explain how your guarantees hold in a difficult case relevant to this subject. Address: A source that answers one address at a time? Only deny?
What to cover
- 01
Scope and behavior contract
Identify users, required behavior and exclusions. Answer: Block what, where? How big?
- 02
State and interfaces
Define the information owned by the system and the inputs, outputs and errors at its boundaries. Resolve: How fast must a change land? Whose law?
- 03
Capacity and operating targets
Estimate the dominant workload and resource demand with units and explicit assumptions. For a learned system, also state how quality is measured and what data is available.
- 04
Architecture and central flow
Draw or describe the responsibilities needed for an IP and URL Denylist. Trace a representative request, event or job from its input to a visible result; identify durable state owners.
- 05
Failure and boundary walkthrough
Walk through a difficult case step by step, including detection and recovery. Consider: Our own detection? A source that answers one address at a time? Only deny?
- 06
Tradeoffs and operations
Compare a credible alternative using your chosen workload and guarantees. Explain a remaining risk, a signal to watch and when you would change the design.
Worked designs
Explore the architecture and decisions, then build on an example with Coach.
Review rubric
AI feedback uses these criteria. Scores are practice feedback.
Scope and contracts
The scoping questions have explicit, consistent answers.
End-to-end design
State ownership and the central flow satisfy the chosen scope.
Operating evidence
Calculations or evaluations support the declared targets.
Boundaries and tradeoffs
A difficult case and an alternative are traced concretely.
Discussion
Share an approach, ask a question, or tag @Coach.
Loading discussion…