firewall_policies
Creates, updates, deletes, gets or lists a firewall_policies resource.
Overview
| Name | firewall_policies |
| Type | Resource |
| Id | google.compute.firewall_policies |
Fields
The following fields are returned by SELECT queries:
- get
- list
| Name | Datatype | Description |
|---|---|---|
id | string (uint64) | [Output Only] The unique identifier for the resource. This identifier is defined by the server. |
name | string | Name of the resource. For Organization Firewall Policies it's a [Output Only] numeric ID allocated by Google Cloud which uniquely identifies the Organization Firewall Policy. |
associations | array | A list of associations that belong to this firewall policy. |
creationTimestamp | string | Output only. [Output Only] Creation timestamp inRFC3339 text format. |
description | string | An optional description of this resource. Provide this property when you create the resource. |
displayName | string | Deprecated, please use short name instead. User-provided name of the Organization firewall policy. The name should be unique in the organization in which the firewall policy is created. This field is not applicable to network firewall policies. This name must be set on creation and cannot be changed. The name must be 1-63 characters long, and comply with RFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
fingerprint | string (byte) | Specifies a fingerprint for this resource, which is essentially a hash of the metadata's contents and used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update metadata. You must always provide an up-to-date fingerprint hash in order to update or change metadata, otherwise the request will fail with error412 conditionNotMet. To see the latest fingerprint, make get() request to the firewall policy. |
kind | string | Output only. [Output only] Type of the resource. Alwayscompute#firewallPolicyfor firewall policies (default: compute#firewallPolicy) |
packetMirroringRules | array | A list of packet mirroring rules that belong to this policy. |
parent | string | Output only. [Output Only] The parent of the firewall policy. This field is not applicable to network firewall policies. |
policyType | string | The type of the firewall policy. This field can be one of VPC_POLICY, RDMA_ROCE_POLICY or ULL_POLICY. Note: if not specified then VPC_POLICY will be used. (RDMA_ROCE_POLICY, ULL_POLICY, VPC_POLICY) |
region | string | Output only. [Output Only] URL of the region where the regional firewall policy resides. This field is not applicable to global firewall policies. You must specify this field as part of the HTTP request URL. It is not settable as a field in the request body. |
ruleTupleCount | integer (int32) | Output only. [Output Only] Total count of all firewall policy rule tuples. A firewall policy can not exceed a set number of tuples. |
rules | array | A list of rules that belong to this policy. There must always be a default rule (rule with priority 2147483647 and match "*"). If no rules are provided when creating a firewall policy, a default rule with action "allow" will be added. |
selfLink | string | [Output Only] Server-defined URL for the resource. |
selfLinkWithId | string | Output only. [Output Only] Server-defined URL for this resource with the resource id. |
shortName | string | User-provided name of the Organization firewall policy. The name should be unique in the organization in which the firewall policy is created. This field is not applicable to network firewall policies. This name must be set on creation and cannot be changed. The name must be 1-63 characters long, and comply with RFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
| Name | Datatype | Description |
|---|---|---|
id | string | [Output Only] Unique identifier for the resource; defined by the server. |
items | array | A list of FirewallPolicy resources. |
kind | string | Output only. [Output Only] Type of resource. Alwayscompute#firewallPolicyList for listsof FirewallPolicies (default: compute#firewallPolicyList) |
nextPageToken | string | [Output Only] This token allows you to get the next page of results for list requests. If the number of results is larger thanmaxResults, use the nextPageToken as a value for the query parameter pageToken in the next list request. Subsequent list requests will have their own nextPageToken to continue paging through the results. |
warning | object | [Output Only] Informational warning message. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | firewallPolicy | Returns the specified firewall policy. | |
list | select | returnPartialSuccess, maxResults, pageToken, filter, orderBy, parentId | Lists all the policies that have been configured for the specified folder or organization. | |
insert | insert | parentId, requestId | Creates a new policy in the specified project using the data included in the request. | |
patch | update | firewallPolicy | requestId | Patches the specified policy with the data included in the request. |
delete | delete | firewallPolicy | requestId | Deletes the specified policy. |
clone_rules | exec | project, region, firewallPolicy | sourceFirewallPolicy, requestId | Copies rules to the specified network firewall policy. |
move | exec | firewallPolicy | parentId, requestId | Moves the specified firewall policy. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
firewallPolicy | string | |
project | string | |
region | string | |
filter | string | |
maxResults | integer (uint32) | |
orderBy | string | |
pageToken | string | |
parentId | string | |
requestId | string | |
returnPartialSuccess | boolean | |
sourceFirewallPolicy | string |
SELECT examples
- get
- list
Returns the specified firewall policy.
SELECT
id,
name,
associations,
creationTimestamp,
description,
displayName,
fingerprint,
kind,
packetMirroringRules,
parent,
policyType,
region,
ruleTupleCount,
rules,
selfLink,
selfLinkWithId,
shortName
FROM google.compute.firewall_policies
WHERE firewallPolicy = '{{ firewallPolicy }}' -- required
;
Lists all the policies that have been configured for the specified
folder or organization.
SELECT
id,
items,
kind,
nextPageToken,
warning
FROM google.compute.firewall_policies
WHERE returnPartialSuccess = '{{ returnPartialSuccess }}'
AND maxResults = '{{ maxResults }}'
AND pageToken = '{{ pageToken }}'
AND filter = '{{ filter }}'
AND orderBy = '{{ orderBy }}'
AND parentId = '{{ parentId }}'
;
INSERT examples
- insert
- Manifest
Creates a new policy in the specified project using the data included in
the request.
INSERT INTO google.compute.firewall_policies (
data__rules,
data__name,
data__packetMirroringRules,
data__description,
data__policyType,
data__selfLink,
data__id,
data__displayName,
data__fingerprint,
data__shortName,
data__associations,
parentId,
requestId
)
SELECT
'{{ rules }}',
'{{ name }}',
'{{ packetMirroringRules }}',
'{{ description }}',
'{{ policyType }}',
'{{ selfLink }}',
'{{ id }}',
'{{ displayName }}',
'{{ fingerprint }}',
'{{ shortName }}',
'{{ associations }}',
'{{ parentId }}',
'{{ requestId }}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone
;
# Description fields are for documentation purposes
- name: firewall_policies
props:
- name: rules
description: |
A list of rules that belong to this policy.
There must always be a default rule (rule with priority 2147483647 and
match "*"). If no rules are provided when creating a firewall policy, a
default rule with action "allow" will be added.
value:
- description: "{{ description }}"
match:
destIpRanges:
- "{{ destIpRanges }}"
destRegionCodes:
- "{{ destRegionCodes }}"
destFqdns:
- "{{ destFqdns }}"
destNetworkContext: "{{ destNetworkContext }}"
layer4Configs:
- ipProtocol: "{{ ipProtocol }}"
ports: "{{ ports }}"
srcNetworkContext: "{{ srcNetworkContext }}"
srcAddressGroups:
- "{{ srcAddressGroups }}"
srcRegionCodes:
- "{{ srcRegionCodes }}"
destThreatIntelligences:
- "{{ destThreatIntelligences }}"
srcSecureTags:
- name: "{{ name }}"
state: "{{ state }}"
destNetworkType: "{{ destNetworkType }}"
srcFqdns:
- "{{ srcFqdns }}"
srcNetworkType: "{{ srcNetworkType }}"
srcIpRanges:
- "{{ srcIpRanges }}"
srcThreatIntelligences:
- "{{ srcThreatIntelligences }}"
srcNetworks:
- "{{ srcNetworks }}"
destAddressGroups:
- "{{ destAddressGroups }}"
ruleTupleCount: {{ ruleTupleCount }}
priority: {{ priority }}
targetServiceAccounts: "{{ targetServiceAccounts }}"
kind: "{{ kind }}"
targetForwardingRules: "{{ targetForwardingRules }}"
targetResources: "{{ targetResources }}"
action: "{{ action }}"
ruleName: "{{ ruleName }}"
targetSecureTags: "{{ targetSecureTags }}"
enableLogging: {{ enableLogging }}
targetType: "{{ targetType }}"
direction: "{{ direction }}"
securityProfileGroup: "{{ securityProfileGroup }}"
disabled: {{ disabled }}
tlsInspect: {{ tlsInspect }}
- name: name
value: "{{ name }}"
description: |
Name of the resource. For Organization Firewall Policies it's a
[Output Only] numeric ID allocated by Google Cloud which uniquely
identifies the Organization Firewall Policy.
- name: packetMirroringRules
description: |
A list of packet mirroring rules that belong to this policy.
value:
- description: "{{ description }}"
match:
destIpRanges:
- "{{ destIpRanges }}"
destRegionCodes:
- "{{ destRegionCodes }}"
destFqdns:
- "{{ destFqdns }}"
destNetworkContext: "{{ destNetworkContext }}"
layer4Configs:
- ipProtocol: "{{ ipProtocol }}"
ports: "{{ ports }}"
srcNetworkContext: "{{ srcNetworkContext }}"
srcAddressGroups:
- "{{ srcAddressGroups }}"
srcRegionCodes:
- "{{ srcRegionCodes }}"
destThreatIntelligences:
- "{{ destThreatIntelligences }}"
srcSecureTags:
- name: "{{ name }}"
state: "{{ state }}"
destNetworkType: "{{ destNetworkType }}"
srcFqdns:
- "{{ srcFqdns }}"
srcNetworkType: "{{ srcNetworkType }}"
srcIpRanges:
- "{{ srcIpRanges }}"
srcThreatIntelligences:
- "{{ srcThreatIntelligences }}"
srcNetworks:
- "{{ srcNetworks }}"
destAddressGroups:
- "{{ destAddressGroups }}"
ruleTupleCount: {{ ruleTupleCount }}
priority: {{ priority }}
targetServiceAccounts: "{{ targetServiceAccounts }}"
kind: "{{ kind }}"
targetForwardingRules: "{{ targetForwardingRules }}"
targetResources: "{{ targetResources }}"
action: "{{ action }}"
ruleName: "{{ ruleName }}"
targetSecureTags: "{{ targetSecureTags }}"
enableLogging: {{ enableLogging }}
targetType: "{{ targetType }}"
direction: "{{ direction }}"
securityProfileGroup: "{{ securityProfileGroup }}"
disabled: {{ disabled }}
tlsInspect: {{ tlsInspect }}
- name: description
value: "{{ description }}"
description: |
An optional description of this resource. Provide this property when you
create the resource.
- name: policyType
value: "{{ policyType }}"
description: |
The type of the firewall policy. This field can be one of
VPC_POLICY, RDMA_ROCE_POLICY or ULL_POLICY.
Note: if not specified then VPC_POLICY will be used.
valid_values: ['RDMA_ROCE_POLICY', 'ULL_POLICY', 'VPC_POLICY']
- name: selfLink
value: "{{ selfLink }}"
description: |
[Output Only] Server-defined URL for the resource.
- name: id
value: "{{ id }}"
description: |
[Output Only] The unique identifier for the resource. This identifier is
defined by the server.
- name: displayName
value: "{{ displayName }}"
description: |
Deprecated, please use short name instead. User-provided name of the
Organization firewall policy. The name should be unique in the organization
in which the firewall policy is created.
This field is not applicable to network firewall policies.
This name must be set on creation and cannot be changed.
The name must be 1-63 characters long, and comply
with RFC1035. Specifically, the name must be 1-63 characters
long and match the regular expression `[a-z]([-a-z0-9]*[a-z0-9])?` which
means the first character must be a lowercase letter, and all following
characters must be a dash, lowercase letter, or digit, except the last
character, which cannot be a dash.
- name: fingerprint
value: "{{ fingerprint }}"
description: |
Specifies a fingerprint for this resource, which is essentially a hash of
the metadata's contents and used for optimistic locking. The
fingerprint is initially generated by Compute Engine and changes after
every request to modify or update metadata. You must always provide an
up-to-date fingerprint hash in order to update or change metadata,
otherwise the request will fail with error412 conditionNotMet.
To see the latest fingerprint, make get() request to the
firewall policy.
- name: shortName
value: "{{ shortName }}"
description: |
User-provided name of the Organization firewall policy. The name should be
unique in the organization in which the firewall policy is created.
This field is not applicable to network firewall policies.
This name must be set on creation and cannot be changed. The name must be
1-63 characters long, and comply with RFC1035.
Specifically, the name must be 1-63 characters long and match the regular
expression `[a-z]([-a-z0-9]*[a-z0-9])?` which means the first
character must be a lowercase letter, and all following characters must
be a dash, lowercase letter, or digit, except the last character, which
cannot be a dash.
- name: associations
description: |
A list of associations that belong to this firewall policy.
value:
- name: "{{ name }}"
shortName: "{{ shortName }}"
firewallPolicyId: "{{ firewallPolicyId }}"
displayName: "{{ displayName }}"
attachmentTarget: "{{ attachmentTarget }}"
- name: parentId
value: "{{ parentId }}"
- name: requestId
value: "{{ requestId }}"
UPDATE examples
- patch
Patches the specified policy with the data included in the request.
UPDATE google.compute.firewall_policies
SET
data__rules = '{{ rules }}',
data__name = '{{ name }}',
data__packetMirroringRules = '{{ packetMirroringRules }}',
data__description = '{{ description }}',
data__policyType = '{{ policyType }}',
data__selfLink = '{{ selfLink }}',
data__id = '{{ id }}',
data__displayName = '{{ displayName }}',
data__fingerprint = '{{ fingerprint }}',
data__shortName = '{{ shortName }}',
data__associations = '{{ associations }}'
WHERE
firewallPolicy = '{{ firewallPolicy }}' --required
AND requestId = '{{ requestId}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
DELETE examples
- delete
Deletes the specified policy.
DELETE FROM google.compute.firewall_policies
WHERE firewallPolicy = '{{ firewallPolicy }}' --required
AND requestId = '{{ requestId }}'
;
Lifecycle Methods
- clone_rules
- move
Copies rules to the specified network firewall policy.
EXEC google.compute.firewall_policies.clone_rules
@project='{{ project }}' --required,
@region='{{ region }}' --required,
@firewallPolicy='{{ firewallPolicy }}' --required,
@sourceFirewallPolicy='{{ sourceFirewallPolicy }}',
@requestId='{{ requestId }}'
;
Moves the specified firewall policy.
EXEC google.compute.firewall_policies.move
@firewallPolicy='{{ firewallPolicy }}' --required,
@parentId='{{ parentId }}',
@requestId='{{ requestId }}'
;