pub struct RegionSecurityPolicyArgs {
pub ddos_protection_config: Output<Option<RegionSecurityPolicyDdosProtectionConfig>>,
pub description: Output<Option<String>>,
pub name: Output<Option<String>>,
pub project: Output<Option<String>>,
pub region: Output<Option<String>>,
pub rules: Output<Option<Vec<RegionSecurityPolicyRule>>>,
pub type_: Output<Option<String>>,
pub user_defined_fields: Output<Option<Vec<RegionSecurityPolicyUserDefinedField>>>,
}
Fields§
§ddos_protection_config: Output<Option<RegionSecurityPolicyDdosProtectionConfig>>
Configuration for Google Cloud Armor DDOS Proctection Config. Structure is documented below.
description: Output<Option<String>>
An optional description of this resource. Provide this property when you create the resource.
name: Output<Option<String>>
Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply with RFC1035. Specifically, the name must be 1-63 characters long and match the regular expression a-z? which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash.
project: Output<Option<String>>
The ID of the project in which the resource belongs. If it is not provided, the provider project is used.
region: Output<Option<String>>
The Region in which the created Region Security Policy should reside. If it is not provided, the provider region is used.
rules: Output<Option<Vec<RegionSecurityPolicyRule>>>
The set of rules that belong to this policy. There must always be a default rule (rule with priority 2147483647 and match “*”). If no rules are provided when creating a security policy, a default rule with action “allow” will be added. Structure is documented below.
type_: Output<Option<String>>
The type indicates the intended use of the security policy.
- CLOUD_ARMOR: Cloud Armor backend security policies can be configured to filter incoming HTTP requests targeting backend services. They filter requests before they hit the origin servers.
- CLOUD_ARMOR_EDGE: Cloud Armor edge security policies can be configured to filter incoming HTTP requests targeting backend services (including Cloud CDN-enabled) as well as backend buckets (Cloud Storage). They filter requests before the request is served from Google’s cache.
- CLOUD_ARMOR_NETWORK: Cloud Armor network policies can be configured to filter packets targeting network load balancing resources such as backend services, target pools, target instances, and instances with external IPs. They filter requests before the request is served from the application.
This field can be set only at resource creation time.
Possible values are:
CLOUD_ARMOR
,CLOUD_ARMOR_EDGE
,CLOUD_ARMOR_NETWORK
.
user_defined_fields: Output<Option<Vec<RegionSecurityPolicyUserDefinedField>>>
Definitions of user-defined fields for CLOUD_ARMOR_NETWORK policies. A user-defined field consists of up to 4 bytes extracted from a fixed offset in the packet, relative to the IPv4, IPv6, TCP, or UDP header, with an optional mask to select certain bits. Rules may then specify matching values for these fields. Structure is documented below.
Implementations§
source§impl RegionSecurityPolicyArgs
impl RegionSecurityPolicyArgs
sourcepub fn builder() -> RegionSecurityPolicyArgsBuilder
pub fn builder() -> RegionSecurityPolicyArgsBuilder
Create an instance of RegionSecurityPolicyArgs
using the builder syntax
Trait Implementations§
source§impl Clone for RegionSecurityPolicyArgs
impl Clone for RegionSecurityPolicyArgs
source§fn clone(&self) -> RegionSecurityPolicyArgs
fn clone(&self) -> RegionSecurityPolicyArgs
1.0.0 · source§fn clone_from(&mut self, source: &Self)
fn clone_from(&mut self, source: &Self)
source
. Read moreAuto Trait Implementations§
impl Freeze for RegionSecurityPolicyArgs
impl RefUnwindSafe for RegionSecurityPolicyArgs
impl Send for RegionSecurityPolicyArgs
impl Sync for RegionSecurityPolicyArgs
impl Unpin for RegionSecurityPolicyArgs
impl UnwindSafe for RegionSecurityPolicyArgs
Blanket Implementations§
source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
source§unsafe fn clone_to_uninit(&self, dst: *mut T)
unsafe fn clone_to_uninit(&self, dst: *mut T)
clone_to_uninit
)