FirewallRule
A FirewallRule is an example API type.
TypeMR
Providerprovider-ionoscloud
Groupcompute.ionoscloud.crossplane.io
Scopecluster
Versionv1alpha1

1apiVersion: compute.ionoscloud.crossplane.io/v1alpha1

2kind: FirewallRule

apiVersion
string
kind
string
metadata
object
spec
object

A FirewallRuleSpec defines the desired state of a FirewallRule.

deletionPolicy
string
forProvider
required
object

FirewallRuleParameters are the observable fields of a FirewallRule. Required values when creating a FirewallRule: DatacenterConfig, ServerConfig, NicConfig, Protocol.

datacenterConfig
required
object

DatacenterConfig contains information about the datacenter resource on which the resource will be created.

datacenterId
string
datacenterIdRef
object

DatacenterIDRef references to a Datacenter to retrieve its ID.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
datacenterIdSelector
object

DatacenterIDSelector selects reference to a Datacenter to retrieve its DatacenterID.

matchControllerRef
boolean
matchLabels
object
policy
object

Policies for selection.

resolution
string
resolve
string
icmpCode
integer
icmpType
integer
name
string
nicConfig
required
object

NicConfig contains information about the nic resource on which the resource will be created.

nicId
string
nicIdRef
object

NicIDRef references to a Nic to retrieve its ID.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
nicIdSelector
object

NicIDSelector selects reference to a Nic to retrieve its NicID.

matchControllerRef
boolean
matchLabels
object
policy
object

Policies for selection.

resolution
string
resolve
string
portRangeEnd
integer
portRangeStart
integer
protocol
required
string
serverConfig
required
object

ServerConfig contains information about the server resource on which the resource will be created.

serverId
string
serverIdRef
object

ServerIDRef references to a Server to retrieve its ID.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
serverIdSelector
object

ServerIDSelector selects reference to a Server to retrieve its ServerID.

matchControllerRef
boolean
matchLabels
object
policy
object

Policies for selection.

resolution
string
resolve
string
sourceIpConfig
object

Only traffic originating from the respective IPv4 address is allowed. Value null allows traffic from any IP address. SourceIP can be set directly or via reference to an IP Block and index.

ip
string
ipBlockConfig
object

Use IpBlockConfig to reference existing IPBlock, and to mention the index for the IP. Index starts from 0 and it must be provided.

index
required
integer
ipBlockId
string
ipBlockIdRef
object

IPBlockIDRef references to a IPBlock to retrieve its ID.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
ipBlockIdSelector
object

IPBlockIDSelector selects reference to a IPBlock to retrieve its IPBlockID.

matchControllerRef
boolean
matchLabels
object
policy
object

Policies for selection.

resolution
string
resolve
string
sourceMac
string
targetIpConfig
object

If the target NIC has multiple IP addresses, only the traffic directed to the respective IP address of the NIC is allowed. Value null allows traffic to any target IP address. TargetIP can be set directly or via reference to an IP Block and index.

ip
string
ipBlockConfig
object

Use IpBlockConfig to reference existing IPBlock, and to mention the index for the IP. Index starts from 0 and it must be provided.

index
required
integer
ipBlockId
string
ipBlockIdRef
object

IPBlockIDRef references to a IPBlock to retrieve its ID.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
ipBlockIdSelector
object

IPBlockIDSelector selects reference to a IPBlock to retrieve its IPBlockID.

matchControllerRef
boolean
matchLabels
object
policy
object

Policies for selection.

resolution
string
resolve
string
type
string
managementPolicies
array

THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. This field is planned to replace the DeletionPolicy field in a future release. Currently, both could be set independently and non-default values would be honored if the feature flag is enabled. If both are custom, the DeletionPolicy field will be ignored. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md

providerConfigRef
object

ProviderConfigReference specifies how the provider that will be used to create, observe, update, and delete this managed resource should be configured.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
publishConnectionDetailsTo
object

PublishConnectionDetailsTo specifies the connection secret config which contains a name, metadata and a reference to secret store config to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.

configRef
object

SecretStoreConfigRef specifies which secret store config should be used for this ConnectionSecret.

name
required
string
policy
object

Policies for referencing.

resolution
string
resolve
string
metadata
object

Metadata is the metadata for connection secret.

annotations
object
labels
object
type
string
name
required
string
writeConnectionSecretToRef
object

WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource. This field is planned to be replaced in a future release in favor of PublishConnectionDetailsTo. Currently, both could be set independently and connection details would be published to both without affecting each other.

name
required
string
namespace
required
string
status
object

A FirewallRuleStatus represents the observed state of a FirewallRule.

atProvider
object

FirewallRuleObservation are the observable fields of a FirewallRule.

firewallRuleId
string
sourceIp
string
state
string
targetIp
string
conditions
array

Conditions of the resource.

lastTransitionTime
required
string
message
string
observedGeneration
integer
reason
required
string
status
required
string
type
required
string
observedGeneration
integer
Discover the building blocks for your internal cloud platform.
© 2026 Upbound, Inc.
Solutions
Learn
Company
Community
More