organization_security_policies
Creates, updates, deletes, gets or lists an organization_security_policies resource.
Overview
| Name | organization_security_policies |
| Type | Resource |
| Id | google.compute.organization_security_policies |
Fields
The following fields are returned by SELECT queries:
- get
- list
| Name | Datatype | Description |
|---|---|---|
id | string (uint64) | Output only. [Output Only] The unique identifier for the resource. This identifier is defined by the server. |
name | string | Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply withRFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
adaptiveProtectionConfig | object | Configuration options for Cloud Armor Adaptive Protection (CAAP). (id: SecurityPolicyAdaptiveProtectionConfig) |
advancedOptionsConfig | object | (id: SecurityPolicyAdvancedOptionsConfig) |
associations | array | A list of associations that belong to this policy. |
creationTimestamp | string | Output only. [Output Only] Creation timestamp inRFC3339 text format. |
ddosProtectionConfig | object | (id: SecurityPolicyDdosProtectionConfig) |
description | string | An optional description of this resource. Provide this property when you create the resource. |
fingerprint | string (byte) | Specifies a fingerprint for this resource, which is essentially a hash of the metadata's contents and used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update metadata. You must always provide an up-to-date fingerprint hash in order to update or change metadata, otherwise the request will fail with error412 conditionNotMet. To see the latest fingerprint, make get() request to the security policy. |
kind | string | Output only. [Output only] Type of the resource. Alwayscompute#securityPolicyfor security policies (default: compute#securityPolicy) |
labelFingerprint | string (byte) | A fingerprint for the labels being applied to this security policy, which is essentially a hash of the labels set used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update labels. You must always provide an up-to-date fingerprint hash in order to update or change labels. To see the latest fingerprint, make get() request to the security policy. |
labels | object | Labels for this resource. These can only be added or modified by thesetLabels method. Each label key/value pair must comply withRFC1035. Label values may be empty. |
parent | string | Output only. [Output Only] The parent of the security policy. |
recaptchaOptionsConfig | object | (id: SecurityPolicyRecaptchaOptionsConfig) |
region | string | Output only. [Output Only] URL of the region where the regional security policy resides. This field is not applicable to global security policies. |
rules | array | A list of rules that belong to this policy. There must always be a default rule which is a rule with priority 2147483647 and match all condition (for the match condition this means match "" for srcIpRanges and for the networkMatch condition every field must be either match "" or not set). If no rules are provided when creating a security policy, a default rule with action "allow" will be added. |
selfLink | string | Output only. [Output Only] Server-defined URL for the resource. |
shortName | string | User-provided name of the organization security policy. The name should be unique in the organization in which the security policy is created. This should only be used when SecurityPolicyType is CLOUD_ARMOR. The name must be 1-63 characters long, and comply with https://www.ietf.org/rfc/rfc1035.txt. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
type | string | The type indicates the intended use of the security policy. - CLOUD_ARMOR: Cloud Armor backend security policies can be configured to filter incoming HTTP requests targeting backend services. They filter requests before they hit the origin servers. - CLOUD_ARMOR_EDGE: Cloud Armor edge security policies can be configured to filter incoming HTTP requests targeting backend services (including Cloud CDN-enabled) as well as backend buckets (Cloud Storage). They filter requests before the request is served from Google's cache. - CLOUD_ARMOR_INTERNAL_SERVICE (preview only): Cloud Armor internal service policies can be configured to filter HTTP requests targeting services managed by Traffic Director in a service mesh. They filter requests before the request is served from the application. - CLOUD_ARMOR_NETWORK: Cloud Armor network policies can be configured to filter packets targeting network load balancing resources such as backend services, target pools, target instances, and instances with external IPs. They filter requests before the request is served from the application. This field can be set only at resource creation time. (CLOUD_ARMOR, CLOUD_ARMOR_EDGE, CLOUD_ARMOR_NETWORK) |
userDefinedFields | array | Definitions of user-defined fields for CLOUD_ARMOR_NETWORK policies. A user-defined field consists of up to 4 bytes extracted from a fixed offset in the packet, relative to the IPv4, IPv6, TCP, or UDP header, with an optional mask to select certain bits. Rules may then specify matching values for these fields. Example: userDefinedFields: - name: "ipv4_fragment_offset" base: IPV4 offset: 6 size: 2 mask: "0x1fff" |
| Name | Datatype | Description |
|---|---|---|
id | string | [Output Only] Unique identifier for the resource; defined by the server. |
items | array | A list of SecurityPolicy resources. |
kind | string | Output only. [Output Only] Type of resource. Alwayscompute#securityPolicyList for listsof securityPolicies (default: compute#securityPolicyList) |
nextPageToken | string | [Output Only] This token allows you to get the next page of results for list requests. If the number of results is larger thanmaxResults, use the nextPageToken as a value for the query parameter pageToken in the next list request. Subsequent list requests will have their own nextPageToken to continue paging through the results. |
warning | object | [Output Only] Informational warning message. |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | securityPolicy | List all of the ordered rules present in a single specified policy. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.get instead. | |
list | select | returnPartialSuccess, parentId, orderBy, filter, maxResults, pageToken | List all the policies that have been configured for the specified organization. Use this API to read Cloud Armor policies. Previously, alpha and beta versions of this API were used to read firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.list instead. | |
insert | insert | parentId, requestId | Creates a new policy in the specified organization using the data included in the request. Use this API to add Cloud Armor policies. Previously, alpha and beta versions of this API were used to add firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.insert instead. | |
patch | update | securityPolicy | requestId | Patches the specified policy with the data included in the request. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patch instead. |
patch_rule | update | securityPolicy | priority, requestId | Patches a rule at the specified priority. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.patchRule instead. |
delete | delete | securityPolicy | requestId | Deletes the specified policy. Use this API to remove Cloud Armor policies. Previously, alpha and beta versions of this API were used to remove firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.delete instead. |
move | exec | securityPolicy | parentId, requestId | Moves the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.move instead. |
copy_rules | exec | securityPolicy | sourceSecurityPolicy, requestId | Copies rules to the specified security policy. Use this API to modify Cloud Armor policies. Previously, alpha and beta versions of this API were used to modify firewall policies. This usage is now disabled for most organizations. Use firewallPolicies.cloneRules instead. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
securityPolicy | string | |
filter | string | |
maxResults | integer (uint32) | |
orderBy | string | |
pageToken | string | |
parentId | string | |
priority | integer (int32) | |
requestId | string | |
returnPartialSuccess | boolean | |
sourceSecurityPolicy | string |
SELECT examples
- get
- list
List all of the ordered rules present in a single specified policy.
Use this API to read Cloud Armor policies. Previously, alpha and beta
versions of this API were used to read firewall policies. This usage is now
disabled for most organizations. Use firewallPolicies.get instead.
SELECT
id,
name,
adaptiveProtectionConfig,
advancedOptionsConfig,
associations,
creationTimestamp,
ddosProtectionConfig,
description,
fingerprint,
kind,
labelFingerprint,
labels,
parent,
recaptchaOptionsConfig,
region,
rules,
selfLink,
shortName,
type,
userDefinedFields
FROM google.compute.organization_security_policies
WHERE securityPolicy = '{{ securityPolicy }}' -- required
;
List all the policies that have been configured for the specified
organization.
Use this API to read Cloud Armor policies. Previously, alpha and beta
versions of this API were used to read firewall policies. This usage is now
disabled for most organizations. Use firewallPolicies.list instead.
SELECT
id,
items,
kind,
nextPageToken,
warning
FROM google.compute.organization_security_policies
WHERE returnPartialSuccess = '{{ returnPartialSuccess }}'
AND parentId = '{{ parentId }}'
AND orderBy = '{{ orderBy }}'
AND filter = '{{ filter }}'
AND maxResults = '{{ maxResults }}'
AND pageToken = '{{ pageToken }}'
;
INSERT examples
- insert
- Manifest
Creates a new policy in the specified organization using the data included
in the request.
Use this API to add Cloud Armor policies. Previously, alpha and beta
versions of this API were used to add firewall policies. This usage is now
disabled for most organizations. Use firewallPolicies.insert instead.
INSERT INTO google.compute.organization_security_policies (
data__recaptchaOptionsConfig,
data__type,
data__labelFingerprint,
data__name,
data__advancedOptionsConfig,
data__rules,
data__userDefinedFields,
data__labels,
data__description,
data__fingerprint,
data__ddosProtectionConfig,
data__associations,
data__adaptiveProtectionConfig,
data__shortName,
parentId,
requestId
)
SELECT
'{{ recaptchaOptionsConfig }}',
'{{ type }}',
'{{ labelFingerprint }}',
'{{ name }}',
'{{ advancedOptionsConfig }}',
'{{ rules }}',
'{{ userDefinedFields }}',
'{{ labels }}',
'{{ description }}',
'{{ fingerprint }}',
'{{ ddosProtectionConfig }}',
'{{ associations }}',
'{{ adaptiveProtectionConfig }}',
'{{ shortName }}',
'{{ parentId }}',
'{{ requestId }}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone
;
# Description fields are for documentation purposes
- name: organization_security_policies
props:
- name: recaptchaOptionsConfig
value:
redirectSiteKey: "{{ redirectSiteKey }}"
- name: type
value: "{{ type }}"
description: |
The type indicates the intended use of the security policy.
- CLOUD_ARMOR: Cloud Armor backend security policies can
be configured to filter incoming HTTP requests targeting backend services.
They filter requests before they hit the origin servers.
- CLOUD_ARMOR_EDGE: Cloud Armor edge security policies can
be configured to filter incoming HTTP requests targeting backend services
(including Cloud CDN-enabled) as well as backend buckets (Cloud Storage).
They filter requests before the request is served from Google's cache.
- CLOUD_ARMOR_INTERNAL_SERVICE (preview only): Cloud Armor
internal service policies can be configured to filter HTTP requests
targeting services managed by Traffic Director in a service mesh. They
filter requests before the request is served from the application.
- CLOUD_ARMOR_NETWORK: Cloud Armor network policies
can be configured to filter packets targeting network load balancing
resources such as backend services, target pools, target instances, and
instances with external IPs. They filter requests before the request is
served from the application.
This field can be set only at resource creation time.
valid_values: ['CLOUD_ARMOR', 'CLOUD_ARMOR_EDGE', 'CLOUD_ARMOR_NETWORK']
- name: labelFingerprint
value: "{{ labelFingerprint }}"
description: |
A fingerprint for the labels being applied to this security policy, which
is essentially a hash of the labels set used for optimistic locking. The
fingerprint is initially generated by Compute Engine and changes after
every request to modify or update labels. You must always provide an
up-to-date fingerprint hash in order to update or change labels.
To see the latest fingerprint, make get() request to the
security policy.
- name: name
value: "{{ name }}"
description: |
Name of the resource. Provided by the client when the resource is created.
The name must be 1-63 characters long, and comply withRFC1035.
Specifically, the name must be 1-63 characters long and match the regular
expression `[a-z]([-a-z0-9]*[a-z0-9])?` which means the first
character must be a lowercase letter, and all following characters must
be a dash, lowercase letter, or digit, except the last character, which
cannot be a dash.
- name: advancedOptionsConfig
value:
jsonParsing: "{{ jsonParsing }}"
logLevel: "{{ logLevel }}"
userIpRequestHeaders:
- "{{ userIpRequestHeaders }}"
jsonCustomConfig:
contentTypes:
- "{{ contentTypes }}"
requestBodyInspectionSize: "{{ requestBodyInspectionSize }}"
- name: rules
description: |
A list of rules that belong to this policy.
There must always be a default rule which is a rule with priority
2147483647 and match all condition (for the match condition this means
match "*" for srcIpRanges and for the networkMatch condition every field
must be either match "*" or not set). If no rules are provided when
creating a security policy, a default rule with action "allow" will be
added.
value:
- networkMatch:
srcIpRanges:
- "{{ srcIpRanges }}"
userDefinedFields:
- name: "{{ name }}"
values: "{{ values }}"
srcRegionCodes:
- "{{ srcRegionCodes }}"
destIpRanges:
- "{{ destIpRanges }}"
srcAsns:
- {{ srcAsns }}
srcPorts:
- "{{ srcPorts }}"
destPorts:
- "{{ destPorts }}"
ipProtocols:
- "{{ ipProtocols }}"
description: "{{ description }}"
match:
expr:
expression: "{{ expression }}"
title: "{{ title }}"
description: "{{ description }}"
location: "{{ location }}"
exprOptions:
recaptchaOptions:
sessionTokenSiteKeys:
- "{{ sessionTokenSiteKeys }}"
actionTokenSiteKeys:
- "{{ actionTokenSiteKeys }}"
versionedExpr: "{{ versionedExpr }}"
config:
srcIpRanges:
- "{{ srcIpRanges }}"
preview: {{ preview }}
preconfiguredWafConfig:
exclusions:
- targetRuleIds: "{{ targetRuleIds }}"
requestHeadersToExclude: "{{ requestHeadersToExclude }}"
requestQueryParamsToExclude: "{{ requestQueryParamsToExclude }}"
targetRuleSet: "{{ targetRuleSet }}"
requestUrisToExclude: "{{ requestUrisToExclude }}"
requestCookiesToExclude: "{{ requestCookiesToExclude }}"
priority: {{ priority }}
rateLimitOptions:
exceedAction: "{{ exceedAction }}"
banDurationSec: {{ banDurationSec }}
exceedRedirectOptions:
target: "{{ target }}"
type: "{{ type }}"
enforceOnKey: "{{ enforceOnKey }}"
enforceOnKeyName: "{{ enforceOnKeyName }}"
banThreshold:
count: {{ count }}
intervalSec: {{ intervalSec }}
rateLimitThreshold:
count: {{ count }}
intervalSec: {{ intervalSec }}
conformAction: "{{ conformAction }}"
enforceOnKeyConfigs:
- enforceOnKeyType: "{{ enforceOnKeyType }}"
enforceOnKeyName: "{{ enforceOnKeyName }}"
kind: "{{ kind }}"
redirectOptions:
target: "{{ target }}"
type: "{{ type }}"
action: "{{ action }}"
headerAction:
requestHeadersToAdds:
- headerName: "{{ headerName }}"
headerValue: "{{ headerValue }}"
- name: userDefinedFields
description: |
Definitions of user-defined fields for CLOUD_ARMOR_NETWORK policies. A
user-defined field consists of up to 4 bytes extracted from a fixed offset
in the packet, relative to the IPv4, IPv6, TCP, or UDP header, with an
optional mask to select certain bits. Rules may then specify matching
values for these fields.
Example:
userDefinedFields:
- name: "ipv4_fragment_offset"
base: IPV4
offset: 6
size: 2
mask: "0x1fff"
value:
- mask: "{{ mask }}"
name: "{{ name }}"
offset: {{ offset }}
size: {{ size }}
base: "{{ base }}"
- name: labels
value: "{{ labels }}"
description: |
Labels for this resource. These can only be added or modified by thesetLabels method. Each label key/value pair must comply withRFC1035.
Label values may be empty.
- name: description
value: "{{ description }}"
description: |
An optional description of this resource. Provide this property when you
create the resource.
- name: fingerprint
value: "{{ fingerprint }}"
description: |
Specifies a fingerprint for this resource, which is essentially a hash of
the metadata's contents and used for optimistic locking. The
fingerprint is initially generated by Compute Engine and changes after
every request to modify or update metadata. You must always provide an
up-to-date fingerprint hash in order to update or change metadata,
otherwise the request will fail with error412 conditionNotMet.
To see the latest fingerprint, make get() request to the
security policy.
- name: ddosProtectionConfig
value:
ddosProtection: "{{ ddosProtection }}"
ddosImpactedBaselineThreshold: {{ ddosImpactedBaselineThreshold }}
ddosAdaptiveProtection: "{{ ddosAdaptiveProtection }}"
- name: associations
description: |
A list of associations that belong to this policy.
value:
- displayName: "{{ displayName }}"
excludedProjects: "{{ excludedProjects }}"
name: "{{ name }}"
shortName: "{{ shortName }}"
attachmentId: "{{ attachmentId }}"
securityPolicyId: "{{ securityPolicyId }}"
excludedFolders: "{{ excludedFolders }}"
- name: adaptiveProtectionConfig
description: |
Configuration options for Cloud Armor Adaptive Protection (CAAP).
value:
layer7DdosDefenseConfig:
enable: {{ enable }}
thresholdConfigs:
- detectionRelativeToBaselineQps: {{ detectionRelativeToBaselineQps }}
autoDeployLoadThreshold: {{ autoDeployLoadThreshold }}
detectionLoadThreshold: {{ detectionLoadThreshold }}
autoDeployExpirationSec: {{ autoDeployExpirationSec }}
autoDeployConfidenceThreshold: {{ autoDeployConfidenceThreshold }}
name: "{{ name }}"
autoDeployImpactedBaselineThreshold: {{ autoDeployImpactedBaselineThreshold }}
trafficGranularityConfigs: "{{ trafficGranularityConfigs }}"
detectionAbsoluteQps: {{ detectionAbsoluteQps }}
ruleVisibility: "{{ ruleVisibility }}"
- name: shortName
value: "{{ shortName }}"
description: |
User-provided name of the organization security policy. The name should be
unique in the organization in which the security policy is created. This
should only be used when SecurityPolicyType is CLOUD_ARMOR.
The name must be 1-63 characters long, and comply with
https://www.ietf.org/rfc/rfc1035.txt. Specifically, the name must be 1-63
characters long and match the regular expression
`[a-z]([-a-z0-9]*[a-z0-9])?` which means the first character must be a
lowercase letter, and all following characters must be a dash, lowercase
letter, or digit, except the last character, which cannot be a dash.
- name: parentId
value: "{{ parentId }}"
- name: requestId
value: "{{ requestId }}"
UPDATE examples
- patch
- patch_rule
Patches the specified policy with the data included in the request.
Use this API to modify Cloud Armor policies. Previously, alpha and beta
versions of this API were used to modify firewall policies. This usage is
now disabled for most organizations. Use firewallPolicies.patch instead.
UPDATE google.compute.organization_security_policies
SET
data__recaptchaOptionsConfig = '{{ recaptchaOptionsConfig }}',
data__type = '{{ type }}',
data__labelFingerprint = '{{ labelFingerprint }}',
data__name = '{{ name }}',
data__advancedOptionsConfig = '{{ advancedOptionsConfig }}',
data__rules = '{{ rules }}',
data__userDefinedFields = '{{ userDefinedFields }}',
data__labels = '{{ labels }}',
data__description = '{{ description }}',
data__fingerprint = '{{ fingerprint }}',
data__ddosProtectionConfig = '{{ ddosProtectionConfig }}',
data__associations = '{{ associations }}',
data__adaptiveProtectionConfig = '{{ adaptiveProtectionConfig }}',
data__shortName = '{{ shortName }}'
WHERE
securityPolicy = '{{ securityPolicy }}' --required
AND requestId = '{{ requestId}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
Patches a rule at the specified priority.
Use this API to modify Cloud Armor policies. Previously, alpha and beta
versions of this API were used to modify firewall policies. This usage is
now disabled for most organizations. Use firewallPolicies.patchRule
instead.
UPDATE google.compute.organization_security_policies
SET
data__networkMatch = '{{ networkMatch }}',
data__description = '{{ description }}',
data__match = '{{ match }}',
data__preview = {{ preview }},
data__preconfiguredWafConfig = '{{ preconfiguredWafConfig }}',
data__priority = {{ priority }},
data__rateLimitOptions = '{{ rateLimitOptions }}',
data__redirectOptions = '{{ redirectOptions }}',
data__action = '{{ action }}',
data__headerAction = '{{ headerAction }}'
WHERE
securityPolicy = '{{ securityPolicy }}' --required
AND priority = '{{ priority}}'
AND requestId = '{{ requestId}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
DELETE examples
- delete
Deletes the specified policy.
Use this API to remove Cloud Armor policies. Previously, alpha and beta
versions of this API were used to remove firewall policies. This usage is
now disabled for most organizations. Use firewallPolicies.delete instead.
DELETE FROM google.compute.organization_security_policies
WHERE securityPolicy = '{{ securityPolicy }}' --required
AND requestId = '{{ requestId }}'
;
Lifecycle Methods
- move
- copy_rules
Moves the specified security policy.
Use this API to modify Cloud Armor policies. Previously, alpha and beta
versions of this API were used to modify firewall policies. This usage is
now disabled for most organizations. Use firewallPolicies.move instead.
EXEC google.compute.organization_security_policies.move
@securityPolicy='{{ securityPolicy }}' --required,
@parentId='{{ parentId }}',
@requestId='{{ requestId }}'
;
Copies rules to the specified security policy.
Use this API to modify Cloud Armor policies. Previously, alpha and beta
versions of this API were used to modify firewall policies. This usage is
now disabled for most organizations. Use firewallPolicies.cloneRules
instead.
EXEC google.compute.organization_security_policies.copy_rules
@securityPolicy='{{ securityPolicy }}' --required,
@sourceSecurityPolicy='{{ sourceSecurityPolicy }}',
@requestId='{{ requestId }}'
;