backend_services
Creates, updates, deletes, gets or lists a backend_services resource.
Overview
| Name | backend_services |
| Type | Resource |
| Id | google.compute.backend_services |
Fields
The following fields are returned by SELECT queries:
- get
- list
- aggregated_list
| Name | Datatype | Description |
|---|---|---|
id | string (uint64) | [Output Only] The unique identifier for the resource. This identifier is defined by the server. |
name | string | Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply withRFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
affinityCookieTtlSec | integer (int32) | Lifetime of cookies in seconds. This setting is applicable to Application Load Balancers and Traffic Director and requires GENERATED_COOKIE or HTTP_COOKIE session affinity. If set to 0, the cookie is non-persistent and lasts only until the end of the browser session (or equivalent). The maximum allowed value is two weeks (1,209,600). Not supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. |
backends | array | The list of backends that serve this BackendService. |
cdnPolicy | object | Cloud CDN configuration for this BackendService. Only available for specified load balancer types. (id: BackendServiceCdnPolicy) |
circuitBreakers | object | Settings controlling the volume of requests, connections and retries to this backend service. (id: CircuitBreakers) |
compressionMode | string | Compress text responses using Brotli or gzip compression, based on the client's Accept-Encoding header. (AUTOMATIC, DISABLED) |
connectionDraining | object | connectionDraining cannot be specified with haPolicy. (id: ConnectionDraining) |
connectionTrackingPolicy | object | Connection Tracking configuration for this BackendService. Connection tracking policy settings are only available for external passthrough Network Load Balancers and internal passthrough Network Load Balancers. connectionTrackingPolicy cannot be specified with haPolicy. (id: BackendServiceConnectionTrackingPolicy) |
consistentHash | object | Consistent Hash-based load balancing can be used to provide soft session affinity based on HTTP headers, cookies or other properties. This load balancing policy is applicable only for HTTP connections. The affinity to a particular destination host will be lost when one or more hosts are added/removed from the destination service. This field specifies parameters that control consistent hashing. This field is only applicable whenlocalityLbPolicy is set to MAGLEV orRING_HASH. This field is applicable to either: - A regional backend service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and load_balancing_scheme set to INTERNAL_MANAGED. - A global backend service with the load_balancing_scheme set to INTERNAL_SELF_MANAGED. (id: ConsistentHashLoadBalancerSettings) |
creationTimestamp | string | Output only. [Output Only] Creation timestamp inRFC3339 text format. |
customMetrics | array | List of custom metrics that are used for theWEIGHTED_ROUND_ROBIN locality_lb_policy. |
customRequestHeaders | array | Headers that the load balancer adds to proxied requests. See Creating custom headers. |
customResponseHeaders | array | Headers that the load balancer adds to proxied responses. See Creating custom headers. |
description | string | An optional description of this resource. Provide this property when you create the resource. |
edgeSecurityPolicy | string | [Output Only] The resource URL for the edge security policy associated with this backend service. |
enableCDN | boolean | If true, enables Cloud CDN for the backend service of a global external Application Load Balancer. |
externalManagedMigrationState | string | Specifies the canary migration state. Possible values are PREPARE, TEST_BY_PERCENTAGE, and TEST_ALL_TRAFFIC. To begin the migration from EXTERNAL to EXTERNAL_MANAGED, the state must be changed to PREPARE. The state must be changed to TEST_ALL_TRAFFIC before the loadBalancingScheme can be changed to EXTERNAL_MANAGED. Optionally, the TEST_BY_PERCENTAGE state can be used to migrate traffic by percentage using externalManagedMigrationTestingPercentage. Rolling back a migration requires the states to be set in reverse order. So changing the scheme from EXTERNAL_MANAGED to EXTERNAL requires the state to be set to TEST_ALL_TRAFFIC at the same time. Optionally, the TEST_BY_PERCENTAGE state can be used to migrate some traffic back to EXTERNAL or PREPARE can be used to migrate all traffic back to EXTERNAL. (PREPARE, TEST_ALL_TRAFFIC, TEST_BY_PERCENTAGE) |
externalManagedMigrationTestingPercentage | number (float) | Determines the fraction of requests that should be processed by the Global external Application Load Balancer. The value of this field must be in the range [0, 100]. Session affinity options will slightly affect this routing behavior, for more details, see:Session Affinity. This value can only be set if the loadBalancingScheme in the BackendService is set to EXTERNAL (when using the classic Application Load Balancer) and the migration state is TEST_BY_PERCENTAGE. |
failoverPolicy | object | Requires at least one backend instance group to be defined as a backup (failover) backend. For load balancers that have configurable failover: Internal passthrough Network Load Balancers and external passthrough Network Load Balancers. failoverPolicy cannot be specified with haPolicy. (id: BackendServiceFailoverPolicy) |
fingerprint | string (byte) | Fingerprint of this resource. A hash of the contents stored in this object. This field is used in optimistic locking. This field will be ignored when inserting a BackendService. An up-to-date fingerprint must be provided in order to update the BackendService, otherwise the request will fail with error 412 conditionNotMet. To see the latest fingerprint, make a get() request to retrieve a BackendService. |
haPolicy | object | Configures self-managed High Availability (HA) for External and Internal Protocol Forwarding. The backends of this regional backend service must only specify zonal network endpoint groups (NEGs) of type GCE_VM_IP. When haPolicy is set for an Internal Passthrough Network Load Balancer, the regional backend service must set the network field. All zonal NEGs must belong to the same network. However, individual NEGs can belong to different subnetworks of that network. When haPolicy is specified, the set of attached network endpoints across all backends comprise an High Availability domain from which one endpoint is selected as the active endpoint (the leader) that receives all traffic. haPolicy can be added only at backend service creation time. Once set up, it cannot be deleted. Note that haPolicy is not for load balancing, and therefore cannot be specified with sessionAffinity, connectionTrackingPolicy, and failoverPolicy. haPolicy requires customers to be responsible for tracking backend endpoint health and electing a leader among the healthy endpoints. Therefore, haPolicy cannot be specified with healthChecks. haPolicy can only be specified for External Passthrough Network Load Balancers and Internal Passthrough Network Load Balancers. (id: BackendServiceHAPolicy) |
healthChecks | array | The list of URLs to the healthChecks, httpHealthChecks (legacy), or httpsHealthChecks (legacy) resource for health checking this backend service. Not all backend services support legacy health checks. See Load balancer guide. Currently, at most one health check can be specified for each backend service. Backend services with instance group or zonal NEG backends must have a health check unless haPolicy is specified. Backend services with internet or serverless NEG backends must not have a health check. healthChecks[] cannot be specified with haPolicy. |
iap | object | The configurations for Identity-Aware Proxy on this resource. Not available for internal passthrough Network Load Balancers and external passthrough Network Load Balancers. (id: BackendServiceIAP) |
ipAddressSelectionPolicy | string | Specifies a preference for traffic sent from the proxy to the backend (or from the client to the backend for proxyless gRPC). The possible values are: - IPV4_ONLY: Only send IPv4 traffic to the backends of the backend service (Instance Group, Managed Instance Group, Network Endpoint Group), regardless of traffic from the client to the proxy. Only IPv4 health checks are used to check the health of the backends. This is the default setting. - PREFER_IPV6: Prioritize the connection to the endpoint's IPv6 address over its IPv4 address (provided there is a healthy IPv6 address). - IPV6_ONLY: Only send IPv6 traffic to the backends of the backend service (Instance Group, Managed Instance Group, Network Endpoint Group), regardless of traffic from the client to the proxy. Only IPv6 health checks are used to check the health of the backends. This field is applicable to either: - Advanced global external Application Load Balancer (load balancing scheme EXTERNAL_MANAGED), - Regional external Application Load Balancer, - Internal proxy Network Load Balancer (load balancing scheme INTERNAL_MANAGED), - Regional internal Application Load Balancer (load balancing scheme INTERNAL_MANAGED), - Traffic Director with Envoy proxies and proxyless gRPC (load balancing scheme INTERNAL_SELF_MANAGED). (IPV4_ONLY, IPV6_ONLY, IP_ADDRESS_SELECTION_POLICY_UNSPECIFIED, PREFER_IPV6) |
kind | string | Output only. [Output Only] Type of resource. Always compute#backendService for backend services. (default: compute#backendService) |
loadBalancingScheme | string | Specifies the load balancer type. A backend service created for one type of load balancer cannot be used with another. For more information, refer toChoosing a load balancer. (EXTERNAL, EXTERNAL_MANAGED, INTERNAL, INTERNAL_MANAGED, INTERNAL_SELF_MANAGED, INVALID_LOAD_BALANCING_SCHEME) |
localityLbPolicies | array | A list of locality load-balancing policies to be used in order of preference. When you use localityLbPolicies, you must set at least one value for either the localityLbPolicies[].policy or the localityLbPolicies[].customPolicy field. localityLbPolicies overrides any value set in the localityLbPolicy field. For an example of how to use this field, seeDefine a list of preferred policies. Caution: This field and its children are intended for use in a service mesh that includes gRPC clients only. Envoy proxies can't use backend services that have this configuration. |
localityLbPolicy | string | The load balancing algorithm used within the scope of the locality. The possible values are: - ROUND_ROBIN: This is a simple policy in which each healthy backend is selected in round robin order. This is the default. - LEAST_REQUEST: An O(1) algorithm which selects two random healthy hosts and picks the host which has fewer active requests. - RING_HASH: The ring/modulo hash load balancer implements consistent hashing to backends. The algorithm has the property that the addition/removal of a host from a set of N hosts only affects 1/N of the requests. - RANDOM: The load balancer selects a random healthy host. - ORIGINAL_DESTINATION: Backend host is selected based on the client connection metadata, i.e., connections are opened to the same address as the destination address of the incoming connection before the connection was redirected to the load balancer. - MAGLEV: used as a drop in replacement for the ring hash load balancer. Maglev is not as stable as ring hash but has faster table lookup build times and host selection times. For more information about Maglev, see Maglev: A Fast and Reliable Software Network Load Balancer. - WEIGHTED_ROUND_ROBIN: Per-endpoint Weighted Round Robin Load Balancing using weights computed from Backend reported Custom Metrics. If set, the Backend Service responses are expected to contain non-standard HTTP response header field Endpoint-Load-Metrics. The reported metrics to use for computing the weights are specified via thecustomMetrics field. This field is applicable to either: - A regional backend service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and load_balancing_scheme set to INTERNAL_MANAGED. - A global backend service with the load_balancing_scheme set to INTERNAL_SELF_MANAGED, INTERNAL_MANAGED, or EXTERNAL_MANAGED. If sessionAffinity is not configured—that is, if session affinity remains at the default value of NONE—then the default value for localityLbPolicy is ROUND_ROBIN. If session affinity is set to a value other than NONE, then the default value for localityLbPolicy isMAGLEV. Only ROUND_ROBIN and RING_HASH are supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. localityLbPolicy cannot be specified with haPolicy. (INVALID_LB_POLICY, LEAST_REQUEST, MAGLEV, ORIGINAL_DESTINATION, RANDOM, RING_HASH, ROUND_ROBIN, WEIGHTED_GCP_RENDEZVOUS, WEIGHTED_MAGLEV, WEIGHTED_ROUND_ROBIN) |
logConfig | object | This field denotes the logging options for the load balancer traffic served by this backend service. If logging is enabled, logs will be exported to Stackdriver. (id: BackendServiceLogConfig) |
maxStreamDuration | object | Specifies the default maximum duration (timeout) for streams to this service. Duration is computed from the beginning of the stream until the response has been completely processed, including all retries. A stream that does not complete in this duration is closed. If not specified, there will be no timeout limit, i.e. the maximum duration is infinite. This value can be overridden in the PathMatcher configuration of the UrlMap that references this backend service. This field is only allowed when the loadBalancingScheme of the backend service is INTERNAL_SELF_MANAGED. (id: Duration) |
metadatas | object | Deployment metadata associated with the resource to be set by a GKE hub controller and read by the backend RCTH |
network | string | The URL of the network to which this backend service belongs. This field must be set for Internal Passthrough Network Load Balancers when the haPolicy is enabled, and for External Passthrough Network Load Balancers when the haPolicy fastIpMove is enabled. This field can only be specified when the load balancing scheme is set toINTERNAL, or when the load balancing scheme is set toEXTERNAL and haPolicy fastIpMove is enabled. |
networkPassThroughLbTrafficPolicy | object | Configures traffic steering properties of internal passthrough Network Load Balancers. networkPassThroughLbTrafficPolicy cannot be specified with haPolicy. (id: BackendServiceNetworkPassThroughLbTrafficPolicy) |
orchestrationInfo | object | Information about the resource or system that manages the backend service. (id: BackendServiceOrchestrationInfo) |
outlierDetection | object | Settings controlling the ejection of unhealthy backend endpoints from the load balancing pool of each individual proxy instance that processes the traffic for the given backend service. If not set, this feature is considered disabled. Results of the outlier detection algorithm (ejection of endpoints from the load balancing pool and returning them back to the pool) are executed independently by each proxy instance of the load balancer. In most cases, more than one proxy instance handles the traffic received by a backend service. Thus, it is possible that an unhealthy endpoint is detected and ejected by only some of the proxies, and while this happens, other proxies may continue to send requests to the same unhealthy endpoint until they detect and eject the unhealthy endpoint. Applicable backend endpoints can be: - VM instances in an Instance Group - Endpoints in a Zonal NEG (GCE_VM_IP, GCE_VM_IP_PORT) - Endpoints in a Hybrid Connectivity NEG (NON_GCP_PRIVATE_IP_PORT) - Serverless NEGs, that resolve to Cloud Run, App Engine, or Cloud Functions Services - Private Service Connect NEGs, that resolve to Google-managed regional API endpoints or managed services published using Private Service Connect Applicable backend service types can be: - A global backend service with the loadBalancingScheme set to INTERNAL_SELF_MANAGED or EXTERNAL_MANAGED. - A regional backend service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and loadBalancingScheme set to INTERNAL_MANAGED or EXTERNAL_MANAGED. Not supported for Serverless NEGs. Not supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. (id: OutlierDetection) |
params | object | Input only. [Input Only] Additional params passed with the request, but not persisted as part of resource payload. (id: BackendServiceParams) |
port | integer (int32) | Deprecated in favor of portName. The TCP port to connect on the backend. The default value is 80. For internal passthrough Network Load Balancers and external passthrough Network Load Balancers, omit port. |
portName | string | A named port on a backend instance group representing the port for communication to the backend VMs in that group. The named port must be defined on each backend instance group. This parameter has no meaning if the backends are NEGs. For internal passthrough Network Load Balancers and external passthrough Network Load Balancers, omit port_name. |
protocol | string | The protocol this BackendService uses to communicate with backends. Possible values are HTTP, HTTPS, HTTP2, H2C, TCP, SSL, UDP or GRPC. depending on the chosen load balancer or Traffic Director configuration. Refer to the documentation for the load balancers or for Traffic Director for more information. Must be set to GRPC when the backend service is referenced by a URL map that is bound to target gRPC proxy. (GRPC, H2C, HTTP, HTTP2, HTTPS, SSL, TCP, UDP, UNSPECIFIED) |
region | string | Output only. [Output Only] URL of the region where the regional backend service resides. This field is not applicable to global backend services. You must specify this field as part of the HTTP request URL. It is not settable as a field in the request body. |
securityPolicy | string | [Output Only] The resource URL for the security policy associated with this backend service. |
securitySettings | object | This field specifies the security settings that apply to this backend service. This field is applicable to a global backend service with the load_balancing_scheme set to INTERNAL_SELF_MANAGED. (id: SecuritySettings) |
selfLink | string | [Output Only] Server-defined URL for the resource. |
serviceBindings | array | URLs of networkservices.ServiceBinding resources. Can only be set if load balancing scheme is INTERNAL_SELF_MANAGED. If set, lists of backends and health checks must be both empty. |
serviceLbPolicy | string | URL to networkservices.ServiceLbPolicy resource. Can only be set if load balancing scheme is EXTERNAL_MANAGED, INTERNAL_MANAGED or INTERNAL_SELF_MANAGED for a global backend service, and EXTERNAL_MANAGED or INTERNAL_MANAGED for a regional backend service. For a global backend service, the service lb policy must be global. For a regional backend service, the service lb policy must be regional and in the same region. |
sessionAffinity | string | Type of session affinity to use. The default is NONE. Only NONE and HEADER_FIELD are supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. For more details, see: Session Affinity. sessionAffinity cannot be specified with haPolicy. (CLIENT_IP, CLIENT_IP_NO_DESTINATION, CLIENT_IP_PORT_PROTO, CLIENT_IP_PROTO, GENERATED_COOKIE, HEADER_FIELD, HTTP_COOKIE, NONE, STRONG_COOKIE_AFFINITY) |
strongSessionAffinityCookie | object | Describes the HTTP cookie used for stateful session affinity. This field is applicable and required if the sessionAffinity is set toSTRONG_COOKIE_AFFINITY. (id: BackendServiceHttpCookie) |
subsetting | object | subsetting cannot be specified with haPolicy. (id: Subsetting) |
timeoutSec | integer (int32) | The backend service timeout has a different meaning depending on the type of load balancer. For more information see, Backend service settings. The default is 30 seconds. The full range of timeout values allowed goes from 1 through 2,147,483,647 seconds. This value can be overridden in the PathMatcher configuration of the UrlMap that references this backend service. Not supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. Instead, use maxStreamDuration. |
tlsSettings | object | Configuration for Backend Authenticated TLS and mTLS. May only be specified when the backend protocol is SSL, HTTPS or HTTP2. (id: BackendServiceTlsSettings) |
usedBy | array | Output only. [Output Only] List of resources referencing given backend service. |
| Name | Datatype | Description |
|---|---|---|
id | string | [Output Only] Unique identifier for the resource; defined by the server. |
items | array | A list of BackendService resources. |
kind | string | Output only. [Output Only] Type of resource. Alwayscompute#backendServiceList for lists of backend services. (default: compute#backendServiceList) |
nextPageToken | string | [Output Only] This token allows you to get the next page of results for list requests. If the number of results is larger thanmaxResults, use the nextPageToken as a value for the query parameter pageToken in the next list request. Subsequent list requests will have their own nextPageToken to continue paging through the results. |
selfLink | string | Output only. [Output Only] Server-defined URL for this resource. |
warning | object | [Output Only] Informational warning message. |
| Name | Datatype | Description |
|---|---|---|
id | string (uint64) | [Output Only] The unique identifier for the resource. This identifier is defined by the server. |
name | string | Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply withRFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
affinityCookieTtlSec | integer (int32) | Lifetime of cookies in seconds. This setting is applicable to Application Load Balancers and Traffic Director and requires GENERATED_COOKIE or HTTP_COOKIE session affinity. If set to 0, the cookie is non-persistent and lasts only until the end of the browser session (or equivalent). The maximum allowed value is two weeks (1,209,600). Not supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. |
backends | array | The list of backends that serve this BackendService. |
cdnPolicy | object | Cloud CDN configuration for this BackendService. Only available for specified load balancer types. (id: BackendServiceCdnPolicy) |
circuitBreakers | object | Settings controlling the volume of requests, connections and retries to this backend service. (id: CircuitBreakers) |
compressionMode | string | Compress text responses using Brotli or gzip compression, based on the client's Accept-Encoding header. (AUTOMATIC, DISABLED) |
connectionDraining | object | connectionDraining cannot be specified with haPolicy. (id: ConnectionDraining) |
connectionTrackingPolicy | object | Connection Tracking configuration for this BackendService. Connection tracking policy settings are only available for external passthrough Network Load Balancers and internal passthrough Network Load Balancers. connectionTrackingPolicy cannot be specified with haPolicy. (id: BackendServiceConnectionTrackingPolicy) |
consistentHash | object | Consistent Hash-based load balancing can be used to provide soft session affinity based on HTTP headers, cookies or other properties. This load balancing policy is applicable only for HTTP connections. The affinity to a particular destination host will be lost when one or more hosts are added/removed from the destination service. This field specifies parameters that control consistent hashing. This field is only applicable whenlocalityLbPolicy is set to MAGLEV orRING_HASH. This field is applicable to either: - A regional backend service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and load_balancing_scheme set to INTERNAL_MANAGED. - A global backend service with the load_balancing_scheme set to INTERNAL_SELF_MANAGED. (id: ConsistentHashLoadBalancerSettings) |
creationTimestamp | string | Output only. [Output Only] Creation timestamp inRFC3339 text format. |
customMetrics | array | List of custom metrics that are used for theWEIGHTED_ROUND_ROBIN locality_lb_policy. |
customRequestHeaders | array | Headers that the load balancer adds to proxied requests. See Creating custom headers. |
customResponseHeaders | array | Headers that the load balancer adds to proxied responses. See Creating custom headers. |
description | string | An optional description of this resource. Provide this property when you create the resource. |
edgeSecurityPolicy | string | [Output Only] The resource URL for the edge security policy associated with this backend service. |
enableCDN | boolean | If true, enables Cloud CDN for the backend service of a global external Application Load Balancer. |
externalManagedMigrationState | string | Specifies the canary migration state. Possible values are PREPARE, TEST_BY_PERCENTAGE, and TEST_ALL_TRAFFIC. To begin the migration from EXTERNAL to EXTERNAL_MANAGED, the state must be changed to PREPARE. The state must be changed to TEST_ALL_TRAFFIC before the loadBalancingScheme can be changed to EXTERNAL_MANAGED. Optionally, the TEST_BY_PERCENTAGE state can be used to migrate traffic by percentage using externalManagedMigrationTestingPercentage. Rolling back a migration requires the states to be set in reverse order. So changing the scheme from EXTERNAL_MANAGED to EXTERNAL requires the state to be set to TEST_ALL_TRAFFIC at the same time. Optionally, the TEST_BY_PERCENTAGE state can be used to migrate some traffic back to EXTERNAL or PREPARE can be used to migrate all traffic back to EXTERNAL. (PREPARE, TEST_ALL_TRAFFIC, TEST_BY_PERCENTAGE) |
externalManagedMigrationTestingPercentage | number (float) | Determines the fraction of requests that should be processed by the Global external Application Load Balancer. The value of this field must be in the range [0, 100]. Session affinity options will slightly affect this routing behavior, for more details, see:Session Affinity. This value can only be set if the loadBalancingScheme in the BackendService is set to EXTERNAL (when using the classic Application Load Balancer) and the migration state is TEST_BY_PERCENTAGE. |
failoverPolicy | object | Requires at least one backend instance group to be defined as a backup (failover) backend. For load balancers that have configurable failover: Internal passthrough Network Load Balancers and external passthrough Network Load Balancers. failoverPolicy cannot be specified with haPolicy. (id: BackendServiceFailoverPolicy) |
fingerprint | string (byte) | Fingerprint of this resource. A hash of the contents stored in this object. This field is used in optimistic locking. This field will be ignored when inserting a BackendService. An up-to-date fingerprint must be provided in order to update the BackendService, otherwise the request will fail with error 412 conditionNotMet. To see the latest fingerprint, make a get() request to retrieve a BackendService. |
haPolicy | object | Configures self-managed High Availability (HA) for External and Internal Protocol Forwarding. The backends of this regional backend service must only specify zonal network endpoint groups (NEGs) of type GCE_VM_IP. When haPolicy is set for an Internal Passthrough Network Load Balancer, the regional backend service must set the network field. All zonal NEGs must belong to the same network. However, individual NEGs can belong to different subnetworks of that network. When haPolicy is specified, the set of attached network endpoints across all backends comprise an High Availability domain from which one endpoint is selected as the active endpoint (the leader) that receives all traffic. haPolicy can be added only at backend service creation time. Once set up, it cannot be deleted. Note that haPolicy is not for load balancing, and therefore cannot be specified with sessionAffinity, connectionTrackingPolicy, and failoverPolicy. haPolicy requires customers to be responsible for tracking backend endpoint health and electing a leader among the healthy endpoints. Therefore, haPolicy cannot be specified with healthChecks. haPolicy can only be specified for External Passthrough Network Load Balancers and Internal Passthrough Network Load Balancers. (id: BackendServiceHAPolicy) |
healthChecks | array | The list of URLs to the healthChecks, httpHealthChecks (legacy), or httpsHealthChecks (legacy) resource for health checking this backend service. Not all backend services support legacy health checks. See Load balancer guide. Currently, at most one health check can be specified for each backend service. Backend services with instance group or zonal NEG backends must have a health check unless haPolicy is specified. Backend services with internet or serverless NEG backends must not have a health check. healthChecks[] cannot be specified with haPolicy. |
iap | object | The configurations for Identity-Aware Proxy on this resource. Not available for internal passthrough Network Load Balancers and external passthrough Network Load Balancers. (id: BackendServiceIAP) |
ipAddressSelectionPolicy | string | Specifies a preference for traffic sent from the proxy to the backend (or from the client to the backend for proxyless gRPC). The possible values are: - IPV4_ONLY: Only send IPv4 traffic to the backends of the backend service (Instance Group, Managed Instance Group, Network Endpoint Group), regardless of traffic from the client to the proxy. Only IPv4 health checks are used to check the health of the backends. This is the default setting. - PREFER_IPV6: Prioritize the connection to the endpoint's IPv6 address over its IPv4 address (provided there is a healthy IPv6 address). - IPV6_ONLY: Only send IPv6 traffic to the backends of the backend service (Instance Group, Managed Instance Group, Network Endpoint Group), regardless of traffic from the client to the proxy. Only IPv6 health checks are used to check the health of the backends. This field is applicable to either: - Advanced global external Application Load Balancer (load balancing scheme EXTERNAL_MANAGED), - Regional external Application Load Balancer, - Internal proxy Network Load Balancer (load balancing scheme INTERNAL_MANAGED), - Regional internal Application Load Balancer (load balancing scheme INTERNAL_MANAGED), - Traffic Director with Envoy proxies and proxyless gRPC (load balancing scheme INTERNAL_SELF_MANAGED). (IPV4_ONLY, IPV6_ONLY, IP_ADDRESS_SELECTION_POLICY_UNSPECIFIED, PREFER_IPV6) |
kind | string | Output only. [Output Only] Type of resource. Always compute#backendService for backend services. (default: compute#backendService) |
loadBalancingScheme | string | Specifies the load balancer type. A backend service created for one type of load balancer cannot be used with another. For more information, refer toChoosing a load balancer. (EXTERNAL, EXTERNAL_MANAGED, INTERNAL, INTERNAL_MANAGED, INTERNAL_SELF_MANAGED, INVALID_LOAD_BALANCING_SCHEME) |
localityLbPolicies | array | A list of locality load-balancing policies to be used in order of preference. When you use localityLbPolicies, you must set at least one value for either the localityLbPolicies[].policy or the localityLbPolicies[].customPolicy field. localityLbPolicies overrides any value set in the localityLbPolicy field. For an example of how to use this field, seeDefine a list of preferred policies. Caution: This field and its children are intended for use in a service mesh that includes gRPC clients only. Envoy proxies can't use backend services that have this configuration. |
localityLbPolicy | string | The load balancing algorithm used within the scope of the locality. The possible values are: - ROUND_ROBIN: This is a simple policy in which each healthy backend is selected in round robin order. This is the default. - LEAST_REQUEST: An O(1) algorithm which selects two random healthy hosts and picks the host which has fewer active requests. - RING_HASH: The ring/modulo hash load balancer implements consistent hashing to backends. The algorithm has the property that the addition/removal of a host from a set of N hosts only affects 1/N of the requests. - RANDOM: The load balancer selects a random healthy host. - ORIGINAL_DESTINATION: Backend host is selected based on the client connection metadata, i.e., connections are opened to the same address as the destination address of the incoming connection before the connection was redirected to the load balancer. - MAGLEV: used as a drop in replacement for the ring hash load balancer. Maglev is not as stable as ring hash but has faster table lookup build times and host selection times. For more information about Maglev, see Maglev: A Fast and Reliable Software Network Load Balancer. - WEIGHTED_ROUND_ROBIN: Per-endpoint Weighted Round Robin Load Balancing using weights computed from Backend reported Custom Metrics. If set, the Backend Service responses are expected to contain non-standard HTTP response header field Endpoint-Load-Metrics. The reported metrics to use for computing the weights are specified via thecustomMetrics field. This field is applicable to either: - A regional backend service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and load_balancing_scheme set to INTERNAL_MANAGED. - A global backend service with the load_balancing_scheme set to INTERNAL_SELF_MANAGED, INTERNAL_MANAGED, or EXTERNAL_MANAGED. If sessionAffinity is not configured—that is, if session affinity remains at the default value of NONE—then the default value for localityLbPolicy is ROUND_ROBIN. If session affinity is set to a value other than NONE, then the default value for localityLbPolicy isMAGLEV. Only ROUND_ROBIN and RING_HASH are supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. localityLbPolicy cannot be specified with haPolicy. (INVALID_LB_POLICY, LEAST_REQUEST, MAGLEV, ORIGINAL_DESTINATION, RANDOM, RING_HASH, ROUND_ROBIN, WEIGHTED_GCP_RENDEZVOUS, WEIGHTED_MAGLEV, WEIGHTED_ROUND_ROBIN) |
logConfig | object | This field denotes the logging options for the load balancer traffic served by this backend service. If logging is enabled, logs will be exported to Stackdriver. (id: BackendServiceLogConfig) |
maxStreamDuration | object | Specifies the default maximum duration (timeout) for streams to this service. Duration is computed from the beginning of the stream until the response has been completely processed, including all retries. A stream that does not complete in this duration is closed. If not specified, there will be no timeout limit, i.e. the maximum duration is infinite. This value can be overridden in the PathMatcher configuration of the UrlMap that references this backend service. This field is only allowed when the loadBalancingScheme of the backend service is INTERNAL_SELF_MANAGED. (id: Duration) |
metadatas | object | Deployment metadata associated with the resource to be set by a GKE hub controller and read by the backend RCTH |
network | string | The URL of the network to which this backend service belongs. This field must be set for Internal Passthrough Network Load Balancers when the haPolicy is enabled, and for External Passthrough Network Load Balancers when the haPolicy fastIpMove is enabled. This field can only be specified when the load balancing scheme is set toINTERNAL, or when the load balancing scheme is set toEXTERNAL and haPolicy fastIpMove is enabled. |
networkPassThroughLbTrafficPolicy | object | Configures traffic steering properties of internal passthrough Network Load Balancers. networkPassThroughLbTrafficPolicy cannot be specified with haPolicy. (id: BackendServiceNetworkPassThroughLbTrafficPolicy) |
orchestrationInfo | object | Information about the resource or system that manages the backend service. (id: BackendServiceOrchestrationInfo) |
outlierDetection | object | Settings controlling the ejection of unhealthy backend endpoints from the load balancing pool of each individual proxy instance that processes the traffic for the given backend service. If not set, this feature is considered disabled. Results of the outlier detection algorithm (ejection of endpoints from the load balancing pool and returning them back to the pool) are executed independently by each proxy instance of the load balancer. In most cases, more than one proxy instance handles the traffic received by a backend service. Thus, it is possible that an unhealthy endpoint is detected and ejected by only some of the proxies, and while this happens, other proxies may continue to send requests to the same unhealthy endpoint until they detect and eject the unhealthy endpoint. Applicable backend endpoints can be: - VM instances in an Instance Group - Endpoints in a Zonal NEG (GCE_VM_IP, GCE_VM_IP_PORT) - Endpoints in a Hybrid Connectivity NEG (NON_GCP_PRIVATE_IP_PORT) - Serverless NEGs, that resolve to Cloud Run, App Engine, or Cloud Functions Services - Private Service Connect NEGs, that resolve to Google-managed regional API endpoints or managed services published using Private Service Connect Applicable backend service types can be: - A global backend service with the loadBalancingScheme set to INTERNAL_SELF_MANAGED or EXTERNAL_MANAGED. - A regional backend service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and loadBalancingScheme set to INTERNAL_MANAGED or EXTERNAL_MANAGED. Not supported for Serverless NEGs. Not supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. (id: OutlierDetection) |
params | object | Input only. [Input Only] Additional params passed with the request, but not persisted as part of resource payload. (id: BackendServiceParams) |
port | integer (int32) | Deprecated in favor of portName. The TCP port to connect on the backend. The default value is 80. For internal passthrough Network Load Balancers and external passthrough Network Load Balancers, omit port. |
portName | string | A named port on a backend instance group representing the port for communication to the backend VMs in that group. The named port must be defined on each backend instance group. This parameter has no meaning if the backends are NEGs. For internal passthrough Network Load Balancers and external passthrough Network Load Balancers, omit port_name. |
protocol | string | The protocol this BackendService uses to communicate with backends. Possible values are HTTP, HTTPS, HTTP2, H2C, TCP, SSL, UDP or GRPC. depending on the chosen load balancer or Traffic Director configuration. Refer to the documentation for the load balancers or for Traffic Director for more information. Must be set to GRPC when the backend service is referenced by a URL map that is bound to target gRPC proxy. (GRPC, H2C, HTTP, HTTP2, HTTPS, SSL, TCP, UDP, UNSPECIFIED) |
region | string | Output only. [Output Only] URL of the region where the regional backend service resides. This field is not applicable to global backend services. You must specify this field as part of the HTTP request URL. It is not settable as a field in the request body. |
securityPolicy | string | [Output Only] The resource URL for the security policy associated with this backend service. |
securitySettings | object | This field specifies the security settings that apply to this backend service. This field is applicable to a global backend service with the load_balancing_scheme set to INTERNAL_SELF_MANAGED. (id: SecuritySettings) |
selfLink | string | [Output Only] Server-defined URL for the resource. |
serviceBindings | array | URLs of networkservices.ServiceBinding resources. Can only be set if load balancing scheme is INTERNAL_SELF_MANAGED. If set, lists of backends and health checks must be both empty. |
serviceLbPolicy | string | URL to networkservices.ServiceLbPolicy resource. Can only be set if load balancing scheme is EXTERNAL_MANAGED, INTERNAL_MANAGED or INTERNAL_SELF_MANAGED for a global backend service, and EXTERNAL_MANAGED or INTERNAL_MANAGED for a regional backend service. For a global backend service, the service lb policy must be global. For a regional backend service, the service lb policy must be regional and in the same region. |
sessionAffinity | string | Type of session affinity to use. The default is NONE. Only NONE and HEADER_FIELD are supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. For more details, see: Session Affinity. sessionAffinity cannot be specified with haPolicy. (CLIENT_IP, CLIENT_IP_NO_DESTINATION, CLIENT_IP_PORT_PROTO, CLIENT_IP_PROTO, GENERATED_COOKIE, HEADER_FIELD, HTTP_COOKIE, NONE, STRONG_COOKIE_AFFINITY) |
strongSessionAffinityCookie | object | Describes the HTTP cookie used for stateful session affinity. This field is applicable and required if the sessionAffinity is set toSTRONG_COOKIE_AFFINITY. (id: BackendServiceHttpCookie) |
subsetting | object | subsetting cannot be specified with haPolicy. (id: Subsetting) |
timeoutSec | integer (int32) | The backend service timeout has a different meaning depending on the type of load balancer. For more information see, Backend service settings. The default is 30 seconds. The full range of timeout values allowed goes from 1 through 2,147,483,647 seconds. This value can be overridden in the PathMatcher configuration of the UrlMap that references this backend service. Not supported when the backend service is referenced by a URL map that is bound to target gRPC proxy that has validateForProxyless field set to true. Instead, use maxStreamDuration. |
tlsSettings | object | Configuration for Backend Authenticated TLS and mTLS. May only be specified when the backend protocol is SSL, HTTPS or HTTP2. (id: BackendServiceTlsSettings) |
usedBy | array | Output only. [Output Only] List of resources referencing given backend service. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | project, region, backendService | Returns the specified regional BackendService resource. | |
list | select | project, region | returnPartialSuccess, orderBy, filter, maxResults, pageToken | Retrieves the list of regional BackendService resources available to the specified project in the given region. |
aggregated_list | select | project | returnPartialSuccess, filter, serviceProjectNumber, maxResults, pageToken, includeAllScopes, orderBy | Retrieves the list of all BackendService resources, regional and global, available to the specified project. To prevent failure, it is recommended that you set the returnPartialSuccess parameter to true. |
insert | insert | project, region | requestId | Creates a regional BackendService resource in the specified project using the data included in the request. For more information, see Backend services overview. |
patch | update | project, region, backendService | requestId | Updates the specified regional BackendService resource with the data included in the request. For more information, see Understanding backend services This method supports PATCH semantics and uses the JSON merge patch format and processing rules. |
update | replace | project, region, backendService | requestId | Updates the specified regional BackendService resource with the data included in the request. For more information, see Backend services overview. |
delete | delete | project, region, backendService | requestId | Deletes the specified regional BackendService resource. |
delete_signed_url_key | exec | project, backendService, keyName | requestId | Deletes a key for validating requests with signed URLs for this backend service. |
set_security_policy | exec | project, region, backendService | requestId | Sets the Google Cloud Armor security policy for the specified backend service. For more information, seeGoogle Cloud Armor Overview |
add_signed_url_key | exec | project, backendService | requestId | Adds a key for validating requests with signed URLs for this backend service. |
get_effective_security_policies | exec | project, backendService | Returns effective security policies applied to this backend service. | |
set_edge_security_policy | exec | project, backendService | requestId | Sets the edge security policy for the specified backend service. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
backendService | string | |
keyName | string | |
project | string | |
region | string | |
filter | string | |
includeAllScopes | boolean | |
maxResults | integer (uint32) | |
orderBy | string | |
pageToken | string | |
requestId | string | |
returnPartialSuccess | boolean | |
serviceProjectNumber | string (int64) |
SELECT examples
- get
- list
- aggregated_list
Returns the specified regional BackendService resource.
SELECT
id,
name,
affinityCookieTtlSec,
backends,
cdnPolicy,
circuitBreakers,
compressionMode,
connectionDraining,
connectionTrackingPolicy,
consistentHash,
creationTimestamp,
customMetrics,
customRequestHeaders,
customResponseHeaders,
description,
edgeSecurityPolicy,
enableCDN,
externalManagedMigrationState,
externalManagedMigrationTestingPercentage,
failoverPolicy,
fingerprint,
haPolicy,
healthChecks,
iap,
ipAddressSelectionPolicy,
kind,
loadBalancingScheme,
localityLbPolicies,
localityLbPolicy,
logConfig,
maxStreamDuration,
metadatas,
network,
networkPassThroughLbTrafficPolicy,
orchestrationInfo,
outlierDetection,
params,
port,
portName,
protocol,
region,
securityPolicy,
securitySettings,
selfLink,
serviceBindings,
serviceLbPolicy,
sessionAffinity,
strongSessionAffinityCookie,
subsetting,
timeoutSec,
tlsSettings,
usedBy
FROM google.compute.backend_services
WHERE project = '{{ project }}' -- required
AND region = '{{ region }}' -- required
AND backendService = '{{ backendService }}' -- required
;
Retrieves the list of regional BackendService resources available to the
specified project in the given region.
SELECT
id,
items,
kind,
nextPageToken,
selfLink,
warning
FROM google.compute.backend_services
WHERE project = '{{ project }}' -- required
AND region = '{{ region }}' -- required
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
AND orderBy = '{{ orderBy }}'
AND filter = '{{ filter }}'
AND maxResults = '{{ maxResults }}'
AND pageToken = '{{ pageToken }}'
;
Retrieves the list of all BackendService resources, regional and global,
available to the specified project.
To prevent failure, it is recommended that you set thereturnPartialSuccess parameter to true.
SELECT
id,
name,
affinityCookieTtlSec,
backends,
cdnPolicy,
circuitBreakers,
compressionMode,
connectionDraining,
connectionTrackingPolicy,
consistentHash,
creationTimestamp,
customMetrics,
customRequestHeaders,
customResponseHeaders,
description,
edgeSecurityPolicy,
enableCDN,
externalManagedMigrationState,
externalManagedMigrationTestingPercentage,
failoverPolicy,
fingerprint,
haPolicy,
healthChecks,
iap,
ipAddressSelectionPolicy,
kind,
loadBalancingScheme,
localityLbPolicies,
localityLbPolicy,
logConfig,
maxStreamDuration,
metadatas,
network,
networkPassThroughLbTrafficPolicy,
orchestrationInfo,
outlierDetection,
params,
port,
portName,
protocol,
region,
securityPolicy,
securitySettings,
selfLink,
serviceBindings,
serviceLbPolicy,
sessionAffinity,
strongSessionAffinityCookie,
subsetting,
timeoutSec,
tlsSettings,
usedBy
FROM google.compute.backend_services
WHERE project = '{{ project }}' -- required
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
AND filter = '{{ filter }}'
AND serviceProjectNumber = '{{ serviceProjectNumber }}'
AND maxResults = '{{ maxResults }}'
AND pageToken = '{{ pageToken }}'
AND includeAllScopes = '{{ includeAllScopes }}'
AND orderBy = '{{ orderBy }}'
;
INSERT examples
- insert
- Manifest
Creates a regional BackendService resource in the specified project using
the data included in the request. For more information, see
Backend services overview.
INSERT INTO google.compute.backend_services (
data__affinityCookieTtlSec,
data__port,
data__network,
data__tlsSettings,
data__ipAddressSelectionPolicy,
data__cdnPolicy,
data__securityPolicy,
data__enableCDN,
data__customMetrics,
data__iap,
data__failoverPolicy,
data__externalManagedMigrationState,
data__networkPassThroughLbTrafficPolicy,
data__consistentHash,
data__logConfig,
data__strongSessionAffinityCookie,
data__sessionAffinity,
data__outlierDetection,
data__customRequestHeaders,
data__compressionMode,
data__metadatas,
data__connectionDraining,
data__serviceBindings,
data__localityLbPolicies,
data__description,
data__subsetting,
data__portName,
data__fingerprint,
data__orchestrationInfo,
data__protocol,
data__haPolicy,
data__edgeSecurityPolicy,
data__params,
data__securitySettings,
data__selfLink,
data__healthChecks,
data__loadBalancingScheme,
data__timeoutSec,
data__backends,
data__serviceLbPolicy,
data__localityLbPolicy,
data__circuitBreakers,
data__externalManagedMigrationTestingPercentage,
data__name,
data__connectionTrackingPolicy,
data__id,
data__maxStreamDuration,
data__customResponseHeaders,
project,
region,
requestId
)
SELECT
{{ affinityCookieTtlSec }},
{{ port }},
'{{ network }}',
'{{ tlsSettings }}',
'{{ ipAddressSelectionPolicy }}',
'{{ cdnPolicy }}',
'{{ securityPolicy }}',
{{ enableCDN }},
'{{ customMetrics }}',
'{{ iap }}',
'{{ failoverPolicy }}',
'{{ externalManagedMigrationState }}',
'{{ networkPassThroughLbTrafficPolicy }}',
'{{ consistentHash }}',
'{{ logConfig }}',
'{{ strongSessionAffinityCookie }}',
'{{ sessionAffinity }}',
'{{ outlierDetection }}',
'{{ customRequestHeaders }}',
'{{ compressionMode }}',
'{{ metadatas }}',
'{{ connectionDraining }}',
'{{ serviceBindings }}',
'{{ localityLbPolicies }}',
'{{ description }}',
'{{ subsetting }}',
'{{ portName }}',
'{{ fingerprint }}',
'{{ orchestrationInfo }}',
'{{ protocol }}',
'{{ haPolicy }}',
'{{ edgeSecurityPolicy }}',
'{{ params }}',
'{{ securitySettings }}',
'{{ selfLink }}',
'{{ healthChecks }}',
'{{ loadBalancingScheme }}',
{{ timeoutSec }},
'{{ backends }}',
'{{ serviceLbPolicy }}',
'{{ localityLbPolicy }}',
'{{ circuitBreakers }}',
{{ externalManagedMigrationTestingPercentage }},
'{{ name }}',
'{{ connectionTrackingPolicy }}',
'{{ id }}',
'{{ maxStreamDuration }}',
'{{ customResponseHeaders }}',
'{{ project }}',
'{{ region }}',
'{{ requestId }}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone
;
# Description fields are for documentation purposes
- name: backend_services
props:
- name: project
value: "{{ project }}"
description: Required parameter for the backend_services resource.
- name: region
value: "{{ region }}"
description: Required parameter for the backend_services resource.
- name: affinityCookieTtlSec
value: {{ affinityCookieTtlSec }}
description: |
Lifetime of cookies in seconds. This setting is applicable to Application
Load Balancers and Traffic Director and requires
GENERATED_COOKIE or HTTP_COOKIE session affinity.
If set to 0, the cookie is non-persistent and lasts only until
the end of the browser session (or equivalent). The maximum allowed value
is two weeks (1,209,600).
Not supported when the backend service is referenced by a URL map that is
bound to target gRPC proxy that has validateForProxyless field set to true.
- name: port
value: {{ port }}
description: |
Deprecated in favor of portName. The TCP port to connect on
the backend. The default value is 80.
For internal passthrough Network Load Balancers and external passthrough
Network Load Balancers, omit port.
- name: network
value: "{{ network }}"
description: |
The URL of the network to which this backend service belongs.
This field must be set for Internal Passthrough Network Load Balancers when
the haPolicy is enabled, and for External Passthrough Network Load
Balancers when the haPolicy fastIpMove is enabled.
This field can only be specified when the load balancing scheme is set toINTERNAL, or when the load balancing scheme is set toEXTERNAL and haPolicy fastIpMove is enabled.
- name: tlsSettings
description: |
Configuration for Backend Authenticated TLS and mTLS. May only be specified
when the backend protocol is SSL, HTTPS or HTTP2.
value:
sni: "{{ sni }}"
subjectAltNames:
- dnsName: "{{ dnsName }}"
uniformResourceIdentifier: "{{ uniformResourceIdentifier }}"
authenticationConfig: "{{ authenticationConfig }}"
- name: ipAddressSelectionPolicy
value: "{{ ipAddressSelectionPolicy }}"
description: |
Specifies a preference for traffic sent from the proxy to the backend (or
from the client to the backend for proxyless gRPC).
The possible values are:
- IPV4_ONLY: Only send IPv4 traffic to the backends of the
backend service (Instance Group, Managed Instance Group, Network Endpoint
Group), regardless of traffic from the client to the proxy. Only IPv4
health checks are used to check the health of the backends. This is the
default setting.
- PREFER_IPV6: Prioritize the connection to the endpoint's
IPv6 address over its IPv4 address (provided there is a healthy IPv6
address).
- IPV6_ONLY: Only send IPv6 traffic to the backends of the
backend service (Instance Group, Managed Instance Group, Network Endpoint
Group), regardless of traffic from the client to the proxy. Only IPv6
health checks are used to check the health of the backends.
This field is applicable to either:
- Advanced global external Application Load Balancer (load balancing
scheme EXTERNAL_MANAGED),
- Regional external Application Load
Balancer,
- Internal proxy Network Load Balancer (load balancing
scheme INTERNAL_MANAGED),
- Regional internal Application Load
Balancer (load balancing scheme INTERNAL_MANAGED),
- Traffic
Director with Envoy proxies and proxyless gRPC (load balancing scheme
INTERNAL_SELF_MANAGED).
valid_values: ['IPV4_ONLY', 'IPV6_ONLY', 'IP_ADDRESS_SELECTION_POLICY_UNSPECIFIED', 'PREFER_IPV6']
- name: cdnPolicy
description: |
Cloud CDN configuration for this BackendService. Only available for
specified load balancer types.
value:
cacheMode: "{{ cacheMode }}"
negativeCaching: {{ negativeCaching }}
bypassCacheOnRequestHeaders:
- headerName: "{{ headerName }}"
cacheKeyPolicy:
includeQueryString: {{ includeQueryString }}
includeNamedCookies:
- "{{ includeNamedCookies }}"
includeProtocol: {{ includeProtocol }}
includeHost: {{ includeHost }}
includeHttpHeaders:
- "{{ includeHttpHeaders }}"
queryStringBlacklist:
- "{{ queryStringBlacklist }}"
queryStringWhitelist:
- "{{ queryStringWhitelist }}"
negativeCachingPolicy:
- ttl: {{ ttl }}
code: {{ code }}
requestCoalescing: {{ requestCoalescing }}
defaultTtl: {{ defaultTtl }}
clientTtl: {{ clientTtl }}
maxTtl: {{ maxTtl }}
signedUrlCacheMaxAgeSec: "{{ signedUrlCacheMaxAgeSec }}"
serveWhileStale: {{ serveWhileStale }}
signedUrlKeyNames:
- "{{ signedUrlKeyNames }}"
- name: securityPolicy
value: "{{ securityPolicy }}"
description: |
[Output Only] The resource URL for the security policy associated with this
backend service.
- name: enableCDN
value: {{ enableCDN }}
description: |
If true, enables Cloud CDN for the backend service of a
global external Application Load Balancer.
- name: customMetrics
description: |
List of custom metrics that are used for theWEIGHTED_ROUND_ROBIN locality_lb_policy.
value:
- name: "{{ name }}"
dryRun: {{ dryRun }}
- name: iap
description: |
The configurations for Identity-Aware Proxy on this resource.
Not available for internal passthrough Network Load Balancers and external
passthrough Network Load Balancers.
value:
oauth2ClientId: "{{ oauth2ClientId }}"
enabled: {{ enabled }}
oauth2ClientSecretSha256: "{{ oauth2ClientSecretSha256 }}"
oauth2ClientSecret: "{{ oauth2ClientSecret }}"
- name: failoverPolicy
description: |
Requires at least one backend instance group to be defined
as a backup (failover) backend.
For load balancers that have configurable failover:
[Internal passthrough Network Load
Balancers](https://cloud.google.com/load-balancing/docs/internal/failover-overview)
and [external passthrough Network Load
Balancers](https://cloud.google.com/load-balancing/docs/network/networklb-failover-overview).
failoverPolicy cannot be specified with haPolicy.
value:
dropTrafficIfUnhealthy: {{ dropTrafficIfUnhealthy }}
disableConnectionDrainOnFailover: {{ disableConnectionDrainOnFailover }}
failoverRatio: {{ failoverRatio }}
- name: externalManagedMigrationState
value: "{{ externalManagedMigrationState }}"
description: |
Specifies the canary migration state. Possible values are PREPARE,
TEST_BY_PERCENTAGE, and TEST_ALL_TRAFFIC.
To begin the migration from EXTERNAL to EXTERNAL_MANAGED, the state must be
changed to PREPARE. The state must be changed to TEST_ALL_TRAFFIC before
the loadBalancingScheme can be changed to EXTERNAL_MANAGED. Optionally, the
TEST_BY_PERCENTAGE state can be used to migrate traffic by percentage using
externalManagedMigrationTestingPercentage.
Rolling back a migration requires the states to be set in reverse order. So
changing the scheme from EXTERNAL_MANAGED to EXTERNAL requires the state to
be set to TEST_ALL_TRAFFIC at the same time. Optionally, the
TEST_BY_PERCENTAGE state can be used to migrate some traffic back to
EXTERNAL or PREPARE can be used to migrate all traffic back to EXTERNAL.
valid_values: ['PREPARE', 'TEST_ALL_TRAFFIC', 'TEST_BY_PERCENTAGE']
- name: networkPassThroughLbTrafficPolicy
description: |
Configures traffic steering properties of internal passthrough Network
Load Balancers.
networkPassThroughLbTrafficPolicy cannot be specified with haPolicy.
value:
zonalAffinity:
spillover: "{{ spillover }}"
spilloverRatio: {{ spilloverRatio }}
- name: consistentHash
description: |
Consistent Hash-based load balancing can be used to provide soft session
affinity based on HTTP headers, cookies or other properties. This load
balancing policy is applicable only for HTTP connections. The affinity to a
particular destination host will be lost when one or more hosts are
added/removed from the destination service. This field specifies parameters
that control consistent hashing. This field is only applicable whenlocalityLbPolicy is set to MAGLEV orRING_HASH.
This field is applicable to either:
- A regional backend service with the service protocol set to HTTP,
HTTPS, HTTP2 or H2C, and load_balancing_scheme set to
INTERNAL_MANAGED.
- A global backend service with the
load_balancing_scheme set to INTERNAL_SELF_MANAGED.
value:
httpCookie:
name: "{{ name }}"
path: "{{ path }}"
ttl:
nanos: {{ nanos }}
seconds: "{{ seconds }}"
httpHeaderName: "{{ httpHeaderName }}"
minimumRingSize: "{{ minimumRingSize }}"
- name: logConfig
description: |
This field denotes the logging options for the load balancer traffic served
by this backend service. If logging is enabled, logs will be exported to
Stackdriver.
value:
loggingHttpRequestHeaders:
- headerName: "{{ headerName }}"
optionalMode: "{{ optionalMode }}"
optionalFields:
- "{{ optionalFields }}"
sampleRate: {{ sampleRate }}
loggingHttpResponseHeaders:
- headerName: "{{ headerName }}"
enable: {{ enable }}
- name: strongSessionAffinityCookie
description: |
Describes the HTTP cookie used for stateful session affinity. This field is
applicable and required if the sessionAffinity is set toSTRONG_COOKIE_AFFINITY.
value:
ttl:
nanos: {{ nanos }}
seconds: "{{ seconds }}"
path: "{{ path }}"
name: "{{ name }}"
- name: sessionAffinity
value: "{{ sessionAffinity }}"
description: |
Type of session affinity to use. The default is NONE.
Only NONE and HEADER_FIELD are supported
when the backend service is referenced by a URL map that is bound to
target gRPC proxy that has validateForProxyless field set to true.
For more details, see:
[Session
Affinity](https://cloud.google.com/load-balancing/docs/backend-service#session_affinity).
sessionAffinity cannot be specified with haPolicy.
valid_values: ['CLIENT_IP', 'CLIENT_IP_NO_DESTINATION', 'CLIENT_IP_PORT_PROTO', 'CLIENT_IP_PROTO', 'GENERATED_COOKIE', 'HEADER_FIELD', 'HTTP_COOKIE', 'NONE', 'STRONG_COOKIE_AFFINITY']
- name: outlierDetection
description: |
Settings controlling the ejection of unhealthy backend endpoints from the
load balancing pool of each individual proxy instance that processes the
traffic for the given backend service. If not set, this feature is
considered disabled.
Results of the outlier detection algorithm (ejection of endpoints from the
load balancing pool and returning them back to the pool) are executed
independently by each proxy instance of the load balancer. In most cases,
more than one proxy instance handles the traffic received by a backend
service. Thus, it is possible that an unhealthy endpoint is detected and
ejected by only some of the proxies, and while this happens, other proxies
may continue to send requests to the same unhealthy endpoint until they
detect and eject the unhealthy endpoint.
Applicable backend endpoints can be:
- VM instances in an Instance Group
- Endpoints in a Zonal NEG (GCE_VM_IP, GCE_VM_IP_PORT)
- Endpoints in a Hybrid Connectivity NEG (NON_GCP_PRIVATE_IP_PORT)
- Serverless NEGs, that resolve to Cloud Run, App Engine, or Cloud
Functions Services
- Private Service Connect NEGs, that resolve to
Google-managed regional API endpoints or managed services published using
Private Service Connect
Applicable backend service types can be:
- A global backend service with the loadBalancingScheme set to
INTERNAL_SELF_MANAGED or EXTERNAL_MANAGED.
- A regional backend
service with the service protocol set to HTTP, HTTPS, HTTP2 or H2C, and
loadBalancingScheme set to INTERNAL_MANAGED or EXTERNAL_MANAGED. Not
supported for Serverless NEGs.
Not supported when the backend service is referenced by a URL map that is
bound to target gRPC proxy that has validateForProxyless field set to true.
value:
interval:
nanos: {{ nanos }}
seconds: "{{ seconds }}"
baseEjectionTime:
nanos: {{ nanos }}
seconds: "{{ seconds }}"
consecutiveGatewayFailure: {{ consecutiveGatewayFailure }}
consecutiveErrors: {{ consecutiveErrors }}
enforcingConsecutiveErrors: {{ enforcingConsecutiveErrors }}
successRateRequestVolume: {{ successRateRequestVolume }}
successRateStdevFactor: {{ successRateStdevFactor }}
maxEjectionPercent: {{ maxEjectionPercent }}
enforcingConsecutiveGatewayFailure: {{ enforcingConsecutiveGatewayFailure }}
enforcingSuccessRate: {{ enforcingSuccessRate }}
successRateMinimumHosts: {{ successRateMinimumHosts }}
- name: customRequestHeaders
value:
- "{{ customRequestHeaders }}"
description: |
Headers that the load balancer adds to proxied requests. See [Creating
custom
headers](https://cloud.google.com/load-balancing/docs/custom-headers).
- name: compressionMode
value: "{{ compressionMode }}"
description: |
Compress text responses using Brotli or gzip compression, based on
the client's Accept-Encoding header.
valid_values: ['AUTOMATIC', 'DISABLED']
- name: metadatas
value: "{{ metadatas }}"
description: |
Deployment metadata associated with the resource to be set by a GKE hub
controller and read by the backend RCTH
- name: connectionDraining
description: |
connectionDraining cannot be specified with haPolicy.
value:
drainingTimeoutSec: {{ drainingTimeoutSec }}
- name: serviceBindings
value:
- "{{ serviceBindings }}"
description: |
URLs of networkservices.ServiceBinding resources.
Can only be set if load balancing scheme is INTERNAL_SELF_MANAGED.
If set, lists of backends and health checks must be both empty.
- name: localityLbPolicies
description: |
A list of locality load-balancing policies to be used in order of
preference. When you use localityLbPolicies, you must set at least one
value for either the localityLbPolicies[].policy or the
localityLbPolicies[].customPolicy field. localityLbPolicies overrides any
value set in the localityLbPolicy field.
For an example of how to use this field, seeDefine
a list of preferred policies.
Caution: This field and its children are intended for use in a service mesh
that includes gRPC clients only. Envoy proxies can't use backend services
that have this configuration.
value:
- customPolicy:
name: "{{ name }}"
data: "{{ data }}"
policy:
name: "{{ name }}"
- name: description
value: "{{ description }}"
description: |
An optional description of this resource. Provide this property when you
create the resource.
- name: subsetting
description: |
subsetting cannot be specified with haPolicy.
value:
policy: "{{ policy }}"
- name: portName
value: "{{ portName }}"
description: |
A named port on a backend instance group representing the port for
communication to the backend VMs in that group. The
named port must be [defined on each backend instance
group](https://cloud.google.com/load-balancing/docs/backend-service#named_ports).
This parameter has no meaning if the backends are NEGs. For internal
passthrough Network Load Balancers and external passthrough Network Load
Balancers, omit port_name.
- name: fingerprint
value: "{{ fingerprint }}"
description: |
Fingerprint of this resource. A hash of the contents stored in this object.
This field is used in optimistic locking. This field will be ignored when
inserting a BackendService. An up-to-date fingerprint must be provided in
order to update the BackendService, otherwise the request will
fail with error 412 conditionNotMet.
To see the latest fingerprint, make a get() request to
retrieve a BackendService.
- name: orchestrationInfo
description: |
Information about the resource or system that manages the backend service.
value:
resourceUri: "{{ resourceUri }}"
- name: protocol
value: "{{ protocol }}"
description: |
The protocol this BackendService uses to communicate
with backends.
Possible values are HTTP, HTTPS, HTTP2, H2C, TCP, SSL, UDP or GRPC.
depending on the chosen load balancer or Traffic Director configuration.
Refer to the documentation for the load balancers or for Traffic Director
for more information.
Must be set to GRPC when the backend service is referenced by a URL map
that is bound to target gRPC proxy.
valid_values: ['GRPC', 'H2C', 'HTTP', 'HTTP2', 'HTTPS', 'SSL', 'TCP', 'UDP', 'UNSPECIFIED']
- name: haPolicy
description: |
Configures self-managed High Availability (HA) for External and Internal
Protocol Forwarding.
The backends of this regional backend service must only specify zonal
network endpoint groups (NEGs) of type GCE_VM_IP.
When haPolicy is set for an Internal Passthrough Network Load Balancer, the
regional backend service must set the network field. All zonal NEGs must
belong to the same network. However, individual NEGs can
belong to different subnetworks of that network.
When haPolicy is specified, the set of attached network endpoints across
all backends comprise an High Availability domain from which one endpoint
is selected as the active endpoint (the leader) that receives all
traffic.
haPolicy can be added only at backend service creation time. Once set up,
it cannot be deleted.
Note that haPolicy is not for load balancing, and therefore cannot be
specified with sessionAffinity, connectionTrackingPolicy, and
failoverPolicy.
haPolicy requires customers to be responsible for tracking backend
endpoint health and electing a leader among the healthy endpoints.
Therefore, haPolicy cannot be specified with healthChecks.
haPolicy can only be specified for External Passthrough Network Load
Balancers and Internal Passthrough Network Load Balancers.
value:
fastIPMove: "{{ fastIPMove }}"
leader:
backendGroup: "{{ backendGroup }}"
networkEndpoint:
instance: "{{ instance }}"
- name: edgeSecurityPolicy
value: "{{ edgeSecurityPolicy }}"
description: |
[Output Only] The resource URL for the edge security policy associated with
this backend service.
- name: params
description: |
Input only. [Input Only] Additional params passed with the request, but not persisted
as part of resource payload.
value:
resourceManagerTags: "{{ resourceManagerTags }}"
- name: securitySettings
description: |
This field specifies the security settings that apply to this backend
service. This field is applicable to a global backend service with the
load_balancing_scheme set to INTERNAL_SELF_MANAGED.
value:
subjectAltNames:
- "{{ subjectAltNames }}"
awsV4Authentication:
accessKeyId: "{{ accessKeyId }}"
accessKey: "{{ accessKey }}"
accessKeyVersion: "{{ accessKeyVersion }}"
originRegion: "{{ originRegion }}"
clientTlsPolicy: "{{ clientTlsPolicy }}"
- name: selfLink
value: "{{ selfLink }}"
description: |
[Output Only] Server-defined URL for the resource.
- name: healthChecks
value:
- "{{ healthChecks }}"
description: |
The list of URLs to the healthChecks, httpHealthChecks (legacy), or
httpsHealthChecks (legacy) resource for health checking this backend
service. Not all backend services support legacy health checks. See
Load balancer guide. Currently, at most one health check can be
specified for each backend service. Backend services with
instance group or zonal NEG backends must have a health check unless
haPolicy is specified. Backend services with internet or serverless NEG
backends must not have a health check.
healthChecks[] cannot be specified with haPolicy.
- name: loadBalancingScheme
value: "{{ loadBalancingScheme }}"
description: |
Specifies the load balancer type. A backend service
created for one type of load balancer cannot be used with another.
For more information, refer toChoosing
a load balancer.
valid_values: ['EXTERNAL', 'EXTERNAL_MANAGED', 'INTERNAL', 'INTERNAL_MANAGED', 'INTERNAL_SELF_MANAGED', 'INVALID_LOAD_BALANCING_SCHEME']
- name: timeoutSec
value: {{ timeoutSec }}
description: |
The backend service timeout has a different meaning depending on the
type of load balancer. For more information see,
Backend service settings.
The default is 30 seconds.
The full range of timeout values allowed goes from 1
through 2,147,483,647 seconds.
This value can be overridden in the PathMatcher configuration of the
UrlMap that references this backend service.
Not supported when the backend service is referenced by a URL map that is
bound to target gRPC proxy that has validateForProxyless field set to true.
Instead, use maxStreamDuration.
- name: backends
description: |
The list of backends that serve this BackendService.
value:
- maxRate: {{ maxRate }}
group: "{{ group }}"
maxConnectionsPerEndpoint: {{ maxConnectionsPerEndpoint }}
maxInFlightRequests: {{ maxInFlightRequests }}
trafficDuration: "{{ trafficDuration }}"
preference: "{{ preference }}"
description: "{{ description }}"
customMetrics: "{{ customMetrics }}"
maxRatePerEndpoint: {{ maxRatePerEndpoint }}
capacityScaler: {{ capacityScaler }}
maxConnections: {{ maxConnections }}
failover: {{ failover }}
maxInFlightRequestsPerEndpoint: {{ maxInFlightRequestsPerEndpoint }}
maxRatePerInstance: {{ maxRatePerInstance }}
balancingMode: "{{ balancingMode }}"
orchestrationInfo:
resourceUri: "{{ resourceUri }}"
maxInFlightRequestsPerInstance: {{ maxInFlightRequestsPerInstance }}
maxConnectionsPerInstance: {{ maxConnectionsPerInstance }}
maxUtilization: {{ maxUtilization }}
- name: serviceLbPolicy
value: "{{ serviceLbPolicy }}"
description: |
URL to networkservices.ServiceLbPolicy resource.
Can only be set if load balancing scheme is EXTERNAL_MANAGED,
INTERNAL_MANAGED or INTERNAL_SELF_MANAGED for a global backend service, and
EXTERNAL_MANAGED or INTERNAL_MANAGED for a regional backend service. For a
global backend service, the service lb policy must be global. For a
regional backend service, the service lb policy must be regional and in the
same region.
- name: localityLbPolicy
value: "{{ localityLbPolicy }}"
description: |
The load balancing algorithm used within the scope of the locality. The
possible values are:
- ROUND_ROBIN: This is a simple policy in which each healthy
backend is selected in round robin order. This is the default.
- LEAST_REQUEST: An O(1) algorithm which
selects two random healthy hosts and picks the host which has fewer active
requests.
- RING_HASH: The ring/modulo hash load balancer implements
consistent hashing to backends. The algorithm has the property that the
addition/removal of a host from a set of N hosts only affects 1/N of the
requests.
- RANDOM: The load balancer selects a random healthy
host.
- ORIGINAL_DESTINATION: Backend host is selected
based on the client connection metadata, i.e., connections are opened to
the same address as the destination address of the incoming connection
before the connection was redirected to the load balancer.
- MAGLEV: used as a drop in replacement for the ring hash
load balancer. Maglev is not as stable as ring hash but has faster table
lookup build times and host selection times. For more information about
Maglev, see Maglev:
A Fast and Reliable Software Network Load Balancer.
- WEIGHTED_ROUND_ROBIN: Per-endpoint Weighted Round Robin
Load Balancing using weights computed from Backend reported Custom Metrics.
If set, the Backend Service responses are expected to contain non-standard
HTTP response header field Endpoint-Load-Metrics. The reported
metrics to use for computing the weights are specified via thecustomMetrics field.
This field is applicable to either:
- A regional backend service with the service protocol set to HTTP,
HTTPS, HTTP2 or H2C, and load_balancing_scheme set to
INTERNAL_MANAGED.
- A global backend service with the
load_balancing_scheme set to INTERNAL_SELF_MANAGED, INTERNAL_MANAGED, or
EXTERNAL_MANAGED.
If sessionAffinity is not configured—that is, if session
affinity remains at the default value of NONE—then the
default value for localityLbPolicy
is ROUND_ROBIN. If session affinity is set to a value other
than NONE,
then the default value for localityLbPolicy isMAGLEV.
Only ROUND_ROBIN and RING_HASH are supported
when the backend service is referenced by a URL map that is bound to
target gRPC proxy that has validateForProxyless field set to true.
localityLbPolicy cannot be specified with haPolicy.
valid_values: ['INVALID_LB_POLICY', 'LEAST_REQUEST', 'MAGLEV', 'ORIGINAL_DESTINATION', 'RANDOM', 'RING_HASH', 'ROUND_ROBIN', 'WEIGHTED_GCP_RENDEZVOUS', 'WEIGHTED_MAGLEV', 'WEIGHTED_ROUND_ROBIN']
- name: circuitBreakers
description: |
Settings controlling the volume of requests, connections and retries to this
backend service.
value:
maxPendingRequests: {{ maxPendingRequests }}
maxRetries: {{ maxRetries }}
maxRequests: {{ maxRequests }}
maxRequestsPerConnection: {{ maxRequestsPerConnection }}
maxConnections: {{ maxConnections }}
- name: externalManagedMigrationTestingPercentage
value: {{ externalManagedMigrationTestingPercentage }}
description: |
Determines the fraction of requests that should be processed by the Global
external Application Load Balancer.
The value of this field must be in the range [0, 100].
Session affinity options will slightly affect this routing behavior, for
more details, see:Session
Affinity.
This value can only be set if the loadBalancingScheme in the BackendService
is set to EXTERNAL (when using the classic Application Load Balancer) and
the migration state is TEST_BY_PERCENTAGE.
- name: name
value: "{{ name }}"
description: |
Name of the resource. Provided by the client when the resource is created.
The name must be 1-63 characters long, and comply withRFC1035.
Specifically, the name must be 1-63 characters long and match the regular
expression `[a-z]([-a-z0-9]*[a-z0-9])?` which means the first
character must be a lowercase letter, and all following characters must
be a dash, lowercase letter, or digit, except the last character, which
cannot be a dash.
- name: connectionTrackingPolicy
description: |
Connection Tracking configuration for this BackendService. Connection
tracking policy settings are only available for external passthrough
Network Load Balancers and internal passthrough Network Load Balancers.
connectionTrackingPolicy cannot be specified with haPolicy.
value:
trackingMode: "{{ trackingMode }}"
connectionPersistenceOnUnhealthyBackends: "{{ connectionPersistenceOnUnhealthyBackends }}"
enableStrongAffinity: {{ enableStrongAffinity }}
idleTimeoutSec: {{ idleTimeoutSec }}
- name: id
value: "{{ id }}"
description: |
[Output Only] The unique identifier for the resource. This identifier is
defined by the server.
- name: maxStreamDuration
description: |
Specifies the default maximum duration (timeout) for streams to this
service. Duration is computed from the beginning of the stream until the
response has been completely processed, including all retries. A stream
that does not complete in this duration is closed.
If not specified, there will be no timeout limit, i.e. the maximum
duration is infinite.
This value can be overridden in the PathMatcher configuration of the
UrlMap that references this backend service.
This field is only allowed when the loadBalancingScheme of
the backend service is INTERNAL_SELF_MANAGED.
value:
nanos: {{ nanos }}
seconds: "{{ seconds }}"
- name: customResponseHeaders
value:
- "{{ customResponseHeaders }}"
description: |
Headers that the load balancer adds to proxied responses. See [Creating
custom
headers](https://cloud.google.com/load-balancing/docs/custom-headers).
- name: requestId
value: "{{ requestId }}"
UPDATE examples
- patch
Updates the specified regional BackendService resource with the data
included in the request. For more information, see
Understanding backend services This method
supports PATCH semantics and uses the JSON merge
patch format and processing rules.
UPDATE google.compute.backend_services
SET
data__affinityCookieTtlSec = {{ affinityCookieTtlSec }},
data__port = {{ port }},
data__network = '{{ network }}',
data__tlsSettings = '{{ tlsSettings }}',
data__ipAddressSelectionPolicy = '{{ ipAddressSelectionPolicy }}',
data__cdnPolicy = '{{ cdnPolicy }}',
data__securityPolicy = '{{ securityPolicy }}',
data__enableCDN = {{ enableCDN }},
data__customMetrics = '{{ customMetrics }}',
data__iap = '{{ iap }}',
data__failoverPolicy = '{{ failoverPolicy }}',
data__externalManagedMigrationState = '{{ externalManagedMigrationState }}',
data__networkPassThroughLbTrafficPolicy = '{{ networkPassThroughLbTrafficPolicy }}',
data__consistentHash = '{{ consistentHash }}',
data__logConfig = '{{ logConfig }}',
data__strongSessionAffinityCookie = '{{ strongSessionAffinityCookie }}',
data__sessionAffinity = '{{ sessionAffinity }}',
data__outlierDetection = '{{ outlierDetection }}',
data__customRequestHeaders = '{{ customRequestHeaders }}',
data__compressionMode = '{{ compressionMode }}',
data__metadatas = '{{ metadatas }}',
data__connectionDraining = '{{ connectionDraining }}',
data__serviceBindings = '{{ serviceBindings }}',
data__localityLbPolicies = '{{ localityLbPolicies }}',
data__description = '{{ description }}',
data__subsetting = '{{ subsetting }}',
data__portName = '{{ portName }}',
data__fingerprint = '{{ fingerprint }}',
data__orchestrationInfo = '{{ orchestrationInfo }}',
data__protocol = '{{ protocol }}',
data__haPolicy = '{{ haPolicy }}',
data__edgeSecurityPolicy = '{{ edgeSecurityPolicy }}',
data__params = '{{ params }}',
data__securitySettings = '{{ securitySettings }}',
data__selfLink = '{{ selfLink }}',
data__healthChecks = '{{ healthChecks }}',
data__loadBalancingScheme = '{{ loadBalancingScheme }}',
data__timeoutSec = {{ timeoutSec }},
data__backends = '{{ backends }}',
data__serviceLbPolicy = '{{ serviceLbPolicy }}',
data__localityLbPolicy = '{{ localityLbPolicy }}',
data__circuitBreakers = '{{ circuitBreakers }}',
data__externalManagedMigrationTestingPercentage = {{ externalManagedMigrationTestingPercentage }},
data__name = '{{ name }}',
data__connectionTrackingPolicy = '{{ connectionTrackingPolicy }}',
data__id = '{{ id }}',
data__maxStreamDuration = '{{ maxStreamDuration }}',
data__customResponseHeaders = '{{ customResponseHeaders }}'
WHERE
project = '{{ project }}' --required
AND region = '{{ region }}' --required
AND backendService = '{{ backendService }}' --required
AND requestId = '{{ requestId}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
REPLACE examples
- update
Updates the specified regional BackendService resource with the data
included in the request. For more information,
see
Backend services overview.
REPLACE google.compute.backend_services
SET
data__affinityCookieTtlSec = {{ affinityCookieTtlSec }},
data__port = {{ port }},
data__network = '{{ network }}',
data__tlsSettings = '{{ tlsSettings }}',
data__ipAddressSelectionPolicy = '{{ ipAddressSelectionPolicy }}',
data__cdnPolicy = '{{ cdnPolicy }}',
data__securityPolicy = '{{ securityPolicy }}',
data__enableCDN = {{ enableCDN }},
data__customMetrics = '{{ customMetrics }}',
data__iap = '{{ iap }}',
data__failoverPolicy = '{{ failoverPolicy }}',
data__externalManagedMigrationState = '{{ externalManagedMigrationState }}',
data__networkPassThroughLbTrafficPolicy = '{{ networkPassThroughLbTrafficPolicy }}',
data__consistentHash = '{{ consistentHash }}',
data__logConfig = '{{ logConfig }}',
data__strongSessionAffinityCookie = '{{ strongSessionAffinityCookie }}',
data__sessionAffinity = '{{ sessionAffinity }}',
data__outlierDetection = '{{ outlierDetection }}',
data__customRequestHeaders = '{{ customRequestHeaders }}',
data__compressionMode = '{{ compressionMode }}',
data__metadatas = '{{ metadatas }}',
data__connectionDraining = '{{ connectionDraining }}',
data__serviceBindings = '{{ serviceBindings }}',
data__localityLbPolicies = '{{ localityLbPolicies }}',
data__description = '{{ description }}',
data__subsetting = '{{ subsetting }}',
data__portName = '{{ portName }}',
data__fingerprint = '{{ fingerprint }}',
data__orchestrationInfo = '{{ orchestrationInfo }}',
data__protocol = '{{ protocol }}',
data__haPolicy = '{{ haPolicy }}',
data__edgeSecurityPolicy = '{{ edgeSecurityPolicy }}',
data__params = '{{ params }}',
data__securitySettings = '{{ securitySettings }}',
data__selfLink = '{{ selfLink }}',
data__healthChecks = '{{ healthChecks }}',
data__loadBalancingScheme = '{{ loadBalancingScheme }}',
data__timeoutSec = {{ timeoutSec }},
data__backends = '{{ backends }}',
data__serviceLbPolicy = '{{ serviceLbPolicy }}',
data__localityLbPolicy = '{{ localityLbPolicy }}',
data__circuitBreakers = '{{ circuitBreakers }}',
data__externalManagedMigrationTestingPercentage = {{ externalManagedMigrationTestingPercentage }},
data__name = '{{ name }}',
data__connectionTrackingPolicy = '{{ connectionTrackingPolicy }}',
data__id = '{{ id }}',
data__maxStreamDuration = '{{ maxStreamDuration }}',
data__customResponseHeaders = '{{ customResponseHeaders }}'
WHERE
project = '{{ project }}' --required
AND region = '{{ region }}' --required
AND backendService = '{{ backendService }}' --required
AND requestId = '{{ requestId}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
DELETE examples
- delete
Deletes the specified regional BackendService resource.
DELETE FROM google.compute.backend_services
WHERE project = '{{ project }}' --required
AND region = '{{ region }}' --required
AND backendService = '{{ backendService }}' --required
AND requestId = '{{ requestId }}'
;
Lifecycle Methods
- delete_signed_url_key
- set_security_policy
- add_signed_url_key
- get_effective_security_policies
- set_edge_security_policy
Deletes a key for validating requests with signed URLs for this backend
service.
EXEC google.compute.backend_services.delete_signed_url_key
@project='{{ project }}' --required,
@backendService='{{ backendService }}' --required,
@keyName='{{ keyName }}' --required,
@requestId='{{ requestId }}'
;
Sets the Google Cloud Armor security policy for the specified backend
service. For more information, seeGoogle
Cloud Armor Overview
EXEC google.compute.backend_services.set_security_policy
@project='{{ project }}' --required,
@region='{{ region }}' --required,
@backendService='{{ backendService }}' --required,
@requestId='{{ requestId }}'
@@json=
'{
"securityPolicy": "{{ securityPolicy }}"
}'
;
Adds a key for validating requests with signed URLs for this backend
service.
EXEC google.compute.backend_services.add_signed_url_key
@project='{{ project }}' --required,
@backendService='{{ backendService }}' --required,
@requestId='{{ requestId }}'
@@json=
'{
"keyValue": "{{ keyValue }}",
"keyName": "{{ keyName }}"
}'
;
Returns effective security policies applied to this backend service.
EXEC google.compute.backend_services.get_effective_security_policies
@project='{{ project }}' --required,
@backendService='{{ backendService }}' --required
;
Sets the edge security policy for the specified backend service.
EXEC google.compute.backend_services.set_edge_security_policy
@project='{{ project }}' --required,
@backendService='{{ backendService }}' --required,
@requestId='{{ requestId }}'
@@json=
'{
"securityPolicy": "{{ securityPolicy }}"
}'
;