security_policies
Creates, updates, deletes, gets or lists a security_policies resource.
Overview
| Name | security_policies |
| Type | Resource |
| Id | google.compute.security_policies |
Fields
The following fields are returned by SELECT queries:
- get
- list
- aggregated_list
| Name | Datatype | Description |
|---|---|---|
id | string (uint64) | Output only. [Output Only] The unique identifier for the resource. This identifier is defined by the server. |
name | string | Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply withRFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
adaptiveProtectionConfig | object | Configuration options for Cloud Armor Adaptive Protection (CAAP). (id: SecurityPolicyAdaptiveProtectionConfig) |
advancedOptionsConfig | object | (id: SecurityPolicyAdvancedOptionsConfig) |
associations | array | A list of associations that belong to this policy. |
creationTimestamp | string | Output only. [Output Only] Creation timestamp inRFC3339 text format. |
ddosProtectionConfig | object | (id: SecurityPolicyDdosProtectionConfig) |
description | string | An optional description of this resource. Provide this property when you create the resource. |
fingerprint | string (byte) | Specifies a fingerprint for this resource, which is essentially a hash of the metadata's contents and used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update metadata. You must always provide an up-to-date fingerprint hash in order to update or change metadata, otherwise the request will fail with error412 conditionNotMet. To see the latest fingerprint, make get() request to the security policy. |
kind | string | Output only. [Output only] Type of the resource. Alwayscompute#securityPolicyfor security policies (default: compute#securityPolicy) |
labelFingerprint | string (byte) | A fingerprint for the labels being applied to this security policy, which is essentially a hash of the labels set used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update labels. You must always provide an up-to-date fingerprint hash in order to update or change labels. To see the latest fingerprint, make get() request to the security policy. |
labels | object | Labels for this resource. These can only be added or modified by thesetLabels method. Each label key/value pair must comply withRFC1035. Label values may be empty. |
parent | string | Output only. [Output Only] The parent of the security policy. |
recaptchaOptionsConfig | object | (id: SecurityPolicyRecaptchaOptionsConfig) |
region | string | Output only. [Output Only] URL of the region where the regional security policy resides. This field is not applicable to global security policies. |
rules | array | A list of rules that belong to this policy. There must always be a default rule which is a rule with priority 2147483647 and match all condition (for the match condition this means match "" for srcIpRanges and for the networkMatch condition every field must be either match "" or not set). If no rules are provided when creating a security policy, a default rule with action "allow" will be added. |
selfLink | string | Output only. [Output Only] Server-defined URL for the resource. |
shortName | string | User-provided name of the organization security policy. The name should be unique in the organization in which the security policy is created. This should only be used when SecurityPolicyType is CLOUD_ARMOR. The name must be 1-63 characters long, and comply with https://www.ietf.org/rfc/rfc1035.txt. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
type | string | The type indicates the intended use of the security policy. - CLOUD_ARMOR: Cloud Armor backend security policies can be configured to filter incoming HTTP requests targeting backend services. They filter requests before they hit the origin servers. - CLOUD_ARMOR_EDGE: Cloud Armor edge security policies can be configured to filter incoming HTTP requests targeting backend services (including Cloud CDN-enabled) as well as backend buckets (Cloud Storage). They filter requests before the request is served from Google's cache. - CLOUD_ARMOR_INTERNAL_SERVICE (preview only): Cloud Armor internal service policies can be configured to filter HTTP requests targeting services managed by Traffic Director in a service mesh. They filter requests before the request is served from the application. - CLOUD_ARMOR_NETWORK: Cloud Armor network policies can be configured to filter packets targeting network load balancing resources such as backend services, target pools, target instances, and instances with external IPs. They filter requests before the request is served from the application. This field can be set only at resource creation time. (CLOUD_ARMOR, CLOUD_ARMOR_EDGE, CLOUD_ARMOR_NETWORK) |
userDefinedFields | array | Definitions of user-defined fields for CLOUD_ARMOR_NETWORK policies. A user-defined field consists of up to 4 bytes extracted from a fixed offset in the packet, relative to the IPv4, IPv6, TCP, or UDP header, with an optional mask to select certain bits. Rules may then specify matching values for these fields. Example: userDefinedFields: - name: "ipv4_fragment_offset" base: IPV4 offset: 6 size: 2 mask: "0x1fff" |
| Name | Datatype | Description |
|---|---|---|
id | string | [Output Only] Unique identifier for the resource; defined by the server. |
items | array | A list of SecurityPolicy resources. |
kind | string | Output only. [Output Only] Type of resource. Alwayscompute#securityPolicyList for listsof securityPolicies (default: compute#securityPolicyList) |
nextPageToken | string | [Output Only] This token allows you to get the next page of results for list requests. If the number of results is larger thanmaxResults, use the nextPageToken as a value for the query parameter pageToken in the next list request. Subsequent list requests will have their own nextPageToken to continue paging through the results. |
warning | object | [Output Only] Informational warning message. |
| Name | Datatype | Description |
|---|---|---|
id | string (uint64) | Output only. [Output Only] The unique identifier for the resource. This identifier is defined by the server. |
name | string | Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply withRFC1035. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
adaptiveProtectionConfig | object | Configuration options for Cloud Armor Adaptive Protection (CAAP). (id: SecurityPolicyAdaptiveProtectionConfig) |
advancedOptionsConfig | object | (id: SecurityPolicyAdvancedOptionsConfig) |
associations | array | A list of associations that belong to this policy. |
creationTimestamp | string | Output only. [Output Only] Creation timestamp inRFC3339 text format. |
ddosProtectionConfig | object | (id: SecurityPolicyDdosProtectionConfig) |
description | string | An optional description of this resource. Provide this property when you create the resource. |
fingerprint | string (byte) | Specifies a fingerprint for this resource, which is essentially a hash of the metadata's contents and used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update metadata. You must always provide an up-to-date fingerprint hash in order to update or change metadata, otherwise the request will fail with error412 conditionNotMet. To see the latest fingerprint, make get() request to the security policy. |
kind | string | Output only. [Output only] Type of the resource. Alwayscompute#securityPolicyfor security policies (default: compute#securityPolicy) |
labelFingerprint | string (byte) | A fingerprint for the labels being applied to this security policy, which is essentially a hash of the labels set used for optimistic locking. The fingerprint is initially generated by Compute Engine and changes after every request to modify or update labels. You must always provide an up-to-date fingerprint hash in order to update or change labels. To see the latest fingerprint, make get() request to the security policy. |
labels | object | Labels for this resource. These can only be added or modified by thesetLabels method. Each label key/value pair must comply withRFC1035. Label values may be empty. |
parent | string | Output only. [Output Only] The parent of the security policy. |
recaptchaOptionsConfig | object | (id: SecurityPolicyRecaptchaOptionsConfig) |
region | string | Output only. [Output Only] URL of the region where the regional security policy resides. This field is not applicable to global security policies. |
rules | array | A list of rules that belong to this policy. There must always be a default rule which is a rule with priority 2147483647 and match all condition (for the match condition this means match "" for srcIpRanges and for the networkMatch condition every field must be either match "" or not set). If no rules are provided when creating a security policy, a default rule with action "allow" will be added. |
selfLink | string | Output only. [Output Only] Server-defined URL for the resource. |
shortName | string | User-provided name of the organization security policy. The name should be unique in the organization in which the security policy is created. This should only be used when SecurityPolicyType is CLOUD_ARMOR. The name must be 1-63 characters long, and comply with https://www.ietf.org/rfc/rfc1035.txt. Specifically, the name must be 1-63 characters long and match the regular expression [a-z]([-a-z0-9]*[a-z0-9])? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash. (pattern: [a-z](?:[-a-z0-9]{0,61}[a-z0-9])?) |
type | string | The type indicates the intended use of the security policy. - CLOUD_ARMOR: Cloud Armor backend security policies can be configured to filter incoming HTTP requests targeting backend services. They filter requests before they hit the origin servers. - CLOUD_ARMOR_EDGE: Cloud Armor edge security policies can be configured to filter incoming HTTP requests targeting backend services (including Cloud CDN-enabled) as well as backend buckets (Cloud Storage). They filter requests before the request is served from Google's cache. - CLOUD_ARMOR_INTERNAL_SERVICE (preview only): Cloud Armor internal service policies can be configured to filter HTTP requests targeting services managed by Traffic Director in a service mesh. They filter requests before the request is served from the application. - CLOUD_ARMOR_NETWORK: Cloud Armor network policies can be configured to filter packets targeting network load balancing resources such as backend services, target pools, target instances, and instances with external IPs. They filter requests before the request is served from the application. This field can be set only at resource creation time. (CLOUD_ARMOR, CLOUD_ARMOR_EDGE, CLOUD_ARMOR_NETWORK) |
userDefinedFields | array | Definitions of user-defined fields for CLOUD_ARMOR_NETWORK policies. A user-defined field consists of up to 4 bytes extracted from a fixed offset in the packet, relative to the IPv4, IPv6, TCP, or UDP header, with an optional mask to select certain bits. Rules may then specify matching values for these fields. Example: userDefinedFields: - name: "ipv4_fragment_offset" base: IPV4 offset: 6 size: 2 mask: "0x1fff" |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | project, securityPolicy | List all of the ordered rules present in a single specified policy. | |
list | select | project | filter, maxResults, pageToken, orderBy, returnPartialSuccess | List all the policies that have been configured for the specified project. |
aggregated_list | select | project | returnPartialSuccess, includeAllScopes, orderBy, maxResults, pageToken, filter, serviceProjectNumber | Retrieves the list of all SecurityPolicy resources, regional and global, available to the specified project. To prevent failure, Google recommends that you set the returnPartialSuccess parameter to true. |
insert | insert | project | requestId, validateOnly | Creates a new policy in the specified project using the data included in the request. |
patch | update | project, securityPolicy | requestId, updateMask | Patches the specified policy with the data included in the request. To clear fields in the policy, leave the fields empty and specify them in the updateMask. This cannot be used to be update the rules in the policy. Please use the per rule methods like addRule, patchRule, and removeRule instead. |
patch_rule | update | project, securityPolicy | updateMask, validateOnly, priority | Patches a rule at the specified priority. To clear fields in the rule, leave the fields empty and specify them in the updateMask. |
delete | delete | project, securityPolicy | requestId | Deletes the specified policy. |
set_labels | exec | project, resource | Sets the labels on a security policy. To learn more about labels, read the Labeling Resources documentation. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
project | string | |
resource | string | |
securityPolicy | string | |
filter | string | |
includeAllScopes | boolean | |
maxResults | integer (uint32) | |
orderBy | string | |
pageToken | string | |
priority | integer (int32) | |
requestId | string | |
returnPartialSuccess | boolean | |
serviceProjectNumber | string (int64) | |
updateMask | string (google-fieldmask) | |
validateOnly | boolean |
SELECT examples
- get
- list
- aggregated_list
List all of the ordered rules present in a single specified policy.
SELECT
id,
name,
adaptiveProtectionConfig,
advancedOptionsConfig,
associations,
creationTimestamp,
ddosProtectionConfig,
description,
fingerprint,
kind,
labelFingerprint,
labels,
parent,
recaptchaOptionsConfig,
region,
rules,
selfLink,
shortName,
type,
userDefinedFields
FROM google.compute.security_policies
WHERE project = '{{ project }}' -- required
AND securityPolicy = '{{ securityPolicy }}' -- required
;
List all the policies that have been configured for the specified project.
SELECT
id,
items,
kind,
nextPageToken,
warning
FROM google.compute.security_policies
WHERE project = '{{ project }}' -- required
AND filter = '{{ filter }}'
AND maxResults = '{{ maxResults }}'
AND pageToken = '{{ pageToken }}'
AND orderBy = '{{ orderBy }}'
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
;
Retrieves the list of all SecurityPolicy resources, regional and global,
available to the specified project.
To prevent failure, Google recommends that you set thereturnPartialSuccess parameter to true.
SELECT
id,
name,
adaptiveProtectionConfig,
advancedOptionsConfig,
associations,
creationTimestamp,
ddosProtectionConfig,
description,
fingerprint,
kind,
labelFingerprint,
labels,
parent,
recaptchaOptionsConfig,
region,
rules,
selfLink,
shortName,
type,
userDefinedFields
FROM google.compute.security_policies
WHERE project = '{{ project }}' -- required
AND returnPartialSuccess = '{{ returnPartialSuccess }}'
AND includeAllScopes = '{{ includeAllScopes }}'
AND orderBy = '{{ orderBy }}'
AND maxResults = '{{ maxResults }}'
AND pageToken = '{{ pageToken }}'
AND filter = '{{ filter }}'
AND serviceProjectNumber = '{{ serviceProjectNumber }}'
;
INSERT examples
- insert
- Manifest
Creates a new policy in the specified project using the data included in
the request.
INSERT INTO google.compute.security_policies (
data__recaptchaOptionsConfig,
data__type,
data__labelFingerprint,
data__name,
data__advancedOptionsConfig,
data__rules,
data__userDefinedFields,
data__labels,
data__description,
data__fingerprint,
data__ddosProtectionConfig,
data__associations,
data__adaptiveProtectionConfig,
data__shortName,
project,
requestId,
validateOnly
)
SELECT
'{{ recaptchaOptionsConfig }}',
'{{ type }}',
'{{ labelFingerprint }}',
'{{ name }}',
'{{ advancedOptionsConfig }}',
'{{ rules }}',
'{{ userDefinedFields }}',
'{{ labels }}',
'{{ description }}',
'{{ fingerprint }}',
'{{ ddosProtectionConfig }}',
'{{ associations }}',
'{{ adaptiveProtectionConfig }}',
'{{ shortName }}',
'{{ project }}',
'{{ requestId }}',
'{{ validateOnly }}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone
;
# Description fields are for documentation purposes
- name: security_policies
props:
- name: project
value: "{{ project }}"
description: Required parameter for the security_policies resource.
- name: recaptchaOptionsConfig
value:
redirectSiteKey: "{{ redirectSiteKey }}"
- name: type
value: "{{ type }}"
description: |
The type indicates the intended use of the security policy.
- CLOUD_ARMOR: Cloud Armor backend security policies can
be configured to filter incoming HTTP requests targeting backend services.
They filter requests before they hit the origin servers.
- CLOUD_ARMOR_EDGE: Cloud Armor edge security policies can
be configured to filter incoming HTTP requests targeting backend services
(including Cloud CDN-enabled) as well as backend buckets (Cloud Storage).
They filter requests before the request is served from Google's cache.
- CLOUD_ARMOR_INTERNAL_SERVICE (preview only): Cloud Armor
internal service policies can be configured to filter HTTP requests
targeting services managed by Traffic Director in a service mesh. They
filter requests before the request is served from the application.
- CLOUD_ARMOR_NETWORK: Cloud Armor network policies
can be configured to filter packets targeting network load balancing
resources such as backend services, target pools, target instances, and
instances with external IPs. They filter requests before the request is
served from the application.
This field can be set only at resource creation time.
valid_values: ['CLOUD_ARMOR', 'CLOUD_ARMOR_EDGE', 'CLOUD_ARMOR_NETWORK']
- name: labelFingerprint
value: "{{ labelFingerprint }}"
description: |
A fingerprint for the labels being applied to this security policy, which
is essentially a hash of the labels set used for optimistic locking. The
fingerprint is initially generated by Compute Engine and changes after
every request to modify or update labels. You must always provide an
up-to-date fingerprint hash in order to update or change labels.
To see the latest fingerprint, make get() request to the
security policy.
- name: name
value: "{{ name }}"
description: |
Name of the resource. Provided by the client when the resource is created.
The name must be 1-63 characters long, and comply withRFC1035.
Specifically, the name must be 1-63 characters long and match the regular
expression `[a-z]([-a-z0-9]*[a-z0-9])?` which means the first
character must be a lowercase letter, and all following characters must
be a dash, lowercase letter, or digit, except the last character, which
cannot be a dash.
- name: advancedOptionsConfig
value:
jsonParsing: "{{ jsonParsing }}"
logLevel: "{{ logLevel }}"
userIpRequestHeaders:
- "{{ userIpRequestHeaders }}"
jsonCustomConfig:
contentTypes:
- "{{ contentTypes }}"
requestBodyInspectionSize: "{{ requestBodyInspectionSize }}"
- name: rules
description: |
A list of rules that belong to this policy.
There must always be a default rule which is a rule with priority
2147483647 and match all condition (for the match condition this means
match "*" for srcIpRanges and for the networkMatch condition every field
must be either match "*" or not set). If no rules are provided when
creating a security policy, a default rule with action "allow" will be
added.
value:
- networkMatch:
srcIpRanges:
- "{{ srcIpRanges }}"
userDefinedFields:
- name: "{{ name }}"
values: "{{ values }}"
srcRegionCodes:
- "{{ srcRegionCodes }}"
destIpRanges:
- "{{ destIpRanges }}"
srcAsns:
- {{ srcAsns }}
srcPorts:
- "{{ srcPorts }}"
destPorts:
- "{{ destPorts }}"
ipProtocols:
- "{{ ipProtocols }}"
description: "{{ description }}"
match:
expr:
expression: "{{ expression }}"
title: "{{ title }}"
description: "{{ description }}"
location: "{{ location }}"
exprOptions:
recaptchaOptions:
sessionTokenSiteKeys:
- "{{ sessionTokenSiteKeys }}"
actionTokenSiteKeys:
- "{{ actionTokenSiteKeys }}"
versionedExpr: "{{ versionedExpr }}"
config:
srcIpRanges:
- "{{ srcIpRanges }}"
preview: {{ preview }}
preconfiguredWafConfig:
exclusions:
- targetRuleIds: "{{ targetRuleIds }}"
requestHeadersToExclude: "{{ requestHeadersToExclude }}"
requestQueryParamsToExclude: "{{ requestQueryParamsToExclude }}"
targetRuleSet: "{{ targetRuleSet }}"
requestUrisToExclude: "{{ requestUrisToExclude }}"
requestCookiesToExclude: "{{ requestCookiesToExclude }}"
priority: {{ priority }}
rateLimitOptions:
exceedAction: "{{ exceedAction }}"
banDurationSec: {{ banDurationSec }}
exceedRedirectOptions:
target: "{{ target }}"
type: "{{ type }}"
enforceOnKey: "{{ enforceOnKey }}"
enforceOnKeyName: "{{ enforceOnKeyName }}"
banThreshold:
count: {{ count }}
intervalSec: {{ intervalSec }}
rateLimitThreshold:
count: {{ count }}
intervalSec: {{ intervalSec }}
conformAction: "{{ conformAction }}"
enforceOnKeyConfigs:
- enforceOnKeyType: "{{ enforceOnKeyType }}"
enforceOnKeyName: "{{ enforceOnKeyName }}"
kind: "{{ kind }}"
redirectOptions:
target: "{{ target }}"
type: "{{ type }}"
action: "{{ action }}"
headerAction:
requestHeadersToAdds:
- headerName: "{{ headerName }}"
headerValue: "{{ headerValue }}"
- name: userDefinedFields
description: |
Definitions of user-defined fields for CLOUD_ARMOR_NETWORK policies. A
user-defined field consists of up to 4 bytes extracted from a fixed offset
in the packet, relative to the IPv4, IPv6, TCP, or UDP header, with an
optional mask to select certain bits. Rules may then specify matching
values for these fields.
Example:
userDefinedFields:
- name: "ipv4_fragment_offset"
base: IPV4
offset: 6
size: 2
mask: "0x1fff"
value:
- mask: "{{ mask }}"
name: "{{ name }}"
offset: {{ offset }}
size: {{ size }}
base: "{{ base }}"
- name: labels
value: "{{ labels }}"
description: |
Labels for this resource. These can only be added or modified by thesetLabels method. Each label key/value pair must comply withRFC1035.
Label values may be empty.
- name: description
value: "{{ description }}"
description: |
An optional description of this resource. Provide this property when you
create the resource.
- name: fingerprint
value: "{{ fingerprint }}"
description: |
Specifies a fingerprint for this resource, which is essentially a hash of
the metadata's contents and used for optimistic locking. The
fingerprint is initially generated by Compute Engine and changes after
every request to modify or update metadata. You must always provide an
up-to-date fingerprint hash in order to update or change metadata,
otherwise the request will fail with error412 conditionNotMet.
To see the latest fingerprint, make get() request to the
security policy.
- name: ddosProtectionConfig
value:
ddosProtection: "{{ ddosProtection }}"
ddosImpactedBaselineThreshold: {{ ddosImpactedBaselineThreshold }}
ddosAdaptiveProtection: "{{ ddosAdaptiveProtection }}"
- name: associations
description: |
A list of associations that belong to this policy.
value:
- displayName: "{{ displayName }}"
excludedProjects: "{{ excludedProjects }}"
name: "{{ name }}"
shortName: "{{ shortName }}"
attachmentId: "{{ attachmentId }}"
securityPolicyId: "{{ securityPolicyId }}"
excludedFolders: "{{ excludedFolders }}"
- name: adaptiveProtectionConfig
description: |
Configuration options for Cloud Armor Adaptive Protection (CAAP).
value:
layer7DdosDefenseConfig:
enable: {{ enable }}
thresholdConfigs:
- detectionRelativeToBaselineQps: {{ detectionRelativeToBaselineQps }}
autoDeployLoadThreshold: {{ autoDeployLoadThreshold }}
detectionLoadThreshold: {{ detectionLoadThreshold }}
autoDeployExpirationSec: {{ autoDeployExpirationSec }}
autoDeployConfidenceThreshold: {{ autoDeployConfidenceThreshold }}
name: "{{ name }}"
autoDeployImpactedBaselineThreshold: {{ autoDeployImpactedBaselineThreshold }}
trafficGranularityConfigs: "{{ trafficGranularityConfigs }}"
detectionAbsoluteQps: {{ detectionAbsoluteQps }}
ruleVisibility: "{{ ruleVisibility }}"
- name: shortName
value: "{{ shortName }}"
description: |
User-provided name of the organization security policy. The name should be
unique in the organization in which the security policy is created. This
should only be used when SecurityPolicyType is CLOUD_ARMOR.
The name must be 1-63 characters long, and comply with
https://www.ietf.org/rfc/rfc1035.txt. Specifically, the name must be 1-63
characters long and match the regular expression
`[a-z]([-a-z0-9]*[a-z0-9])?` which means the first character must be a
lowercase letter, and all following characters must be a dash, lowercase
letter, or digit, except the last character, which cannot be a dash.
- name: requestId
value: "{{ requestId }}"
- name: validateOnly
value: {{ validateOnly }}
UPDATE examples
- patch
- patch_rule
Patches the specified policy with the data included in the request. To
clear fields in the policy, leave the fields empty and specify them in the
updateMask. This cannot be used to be update the rules in the policy.
Please use the per rule methods like addRule, patchRule, and removeRule
instead.
UPDATE google.compute.security_policies
SET
data__recaptchaOptionsConfig = '{{ recaptchaOptionsConfig }}',
data__type = '{{ type }}',
data__labelFingerprint = '{{ labelFingerprint }}',
data__name = '{{ name }}',
data__advancedOptionsConfig = '{{ advancedOptionsConfig }}',
data__rules = '{{ rules }}',
data__userDefinedFields = '{{ userDefinedFields }}',
data__labels = '{{ labels }}',
data__description = '{{ description }}',
data__fingerprint = '{{ fingerprint }}',
data__ddosProtectionConfig = '{{ ddosProtectionConfig }}',
data__associations = '{{ associations }}',
data__adaptiveProtectionConfig = '{{ adaptiveProtectionConfig }}',
data__shortName = '{{ shortName }}'
WHERE
project = '{{ project }}' --required
AND securityPolicy = '{{ securityPolicy }}' --required
AND requestId = '{{ requestId}}'
AND updateMask = '{{ updateMask}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
Patches a rule at the specified priority. To clear fields in the rule,
leave the fields empty and specify them in the updateMask.
UPDATE google.compute.security_policies
SET
data__networkMatch = '{{ networkMatch }}',
data__description = '{{ description }}',
data__match = '{{ match }}',
data__preview = {{ preview }},
data__preconfiguredWafConfig = '{{ preconfiguredWafConfig }}',
data__priority = {{ priority }},
data__rateLimitOptions = '{{ rateLimitOptions }}',
data__redirectOptions = '{{ redirectOptions }}',
data__action = '{{ action }}',
data__headerAction = '{{ headerAction }}'
WHERE
project = '{{ project }}' --required
AND securityPolicy = '{{ securityPolicy }}' --required
AND updateMask = '{{ updateMask}}'
AND validateOnly = {{ validateOnly}}
AND priority = '{{ priority}}'
RETURNING
id,
name,
clientOperationId,
creationTimestamp,
description,
endTime,
error,
getVersionOperationMetadata,
httpErrorMessage,
httpErrorStatusCode,
insertTime,
instancesBulkInsertOperationMetadata,
kind,
operationGroupId,
operationType,
progress,
region,
selfLink,
setCommonInstanceMetadataOperationMetadata,
startTime,
status,
statusMessage,
targetId,
targetLink,
user,
warnings,
zone;
DELETE examples
- delete
Deletes the specified policy.
DELETE FROM google.compute.security_policies
WHERE project = '{{ project }}' --required
AND securityPolicy = '{{ securityPolicy }}' --required
AND requestId = '{{ requestId }}'
;
Lifecycle Methods
- set_labels
Sets the labels on a security policy. To learn more about labels,
read the Labeling Resources
documentation.
EXEC google.compute.security_policies.set_labels
@project='{{ project }}' --required,
@resource='{{ resource }}' --required
@@json=
'{
"labels": "{{ labels }}",
"labelFingerprint": "{{ labelFingerprint }}"
}'
;