1apiVersion: compute.gcp.m.upbound.io/v1beta1
2kind: FirewallPolicyRule
FirewallPolicyRuleSpec defines the desired state of FirewallPolicyRule
(No description available)
Reference to a FirewallPolicy in compute to populate firewallPolicy.
Policies for referencing.
Selector for a FirewallPolicy in compute to populate firewallPolicy.
Policies for selection.
A match condition that incoming traffic is evaluated against. If it evaluates to true, the corresponding 'action' is enforced. Structure is documented below.
Address groups which should be matched against the traffic destination. Maximum number of destination address groups is 10.
References to AddressGroup in networksecurity to populate destAddressGroups.
Policies for referencing.
Selector for a list of AddressGroup in networksecurity to populate destAddressGroups.
Policies for selection.
Fully Qualified Domain Name (FQDN) which should be matched against traffic destination. Maximum number of destination fqdn allowed is 100.
CIDR IP address range. Maximum number of destination CIDR IP ranges allowed is 5000.
Region codes whose IP addresses will be used to match for destination of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of dest region codes allowed is 5000.
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic destination.
Pairs of IP protocols and ports that the rule should match. Structure is documented below.
An optional list of ports to which this rule applies. This field is only applicable for UDP or TCP protocol. Each entry must be either an integer or a range. If not specified, this rule applies to connections through any port.
Address groups which should be matched against the traffic source. Maximum number of source address groups is 10.
Fully Qualified Domain Name (FQDN) which should be matched against traffic source. Maximum number of source fqdn allowed is 100.
CIDR IP address range. Maximum number of source CIDR IP ranges allowed is 5000.
Region codes whose IP addresses will be used to match for source of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of source region codes allowed is 5000.
List of secure tag values, which should be matched at the source of the traffic. For INGRESS rule, if all the srcSecureTag are INEFFECTIVE, and there is no srcIpRange, this rule will be ignored. Maximum number of source tag values allowed is 256. Structure is documented below.
Reference to a TagValue in tags to populate name.
Policies for referencing.
Selector for a TagValue in tags to populate name.
Policies for selection.
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic source.
A list of network resource URLs to which this rule applies. This field allows you to control which network's VMs get this rule. If this field is left blank, all VMs within the organization will receive the rule.
A list of secure tags that controls which instances the firewall rule applies to. If targetSecureTag are specified, then the firewall rule applies only to instances in the VPC network that have one of those EFFECTIVE secure tags, if all the targetSecureTag are in INEFFECTIVE state, then this rule will be ignored. targetSecureTag may not be set at the same time as targetServiceAccounts. If neither targetServiceAccounts nor targetSecureTag are specified, the firewall rule applies to all instances on the specified network. Maximum number of target secure tags allowed is 256. Structure is documented below.
Reference to a TagValue in tags to populate name.
Policies for referencing.
Selector for a TagValue in tags to populate name.
Policies for selection.
A list of service accounts indicating the sets of instances that are applied with this rule.
THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.
Reference to a FirewallPolicy in compute to populate firewallPolicy.
Policies for referencing.
Selector for a FirewallPolicy in compute to populate firewallPolicy.
Policies for selection.
A match condition that incoming traffic is evaluated against. If it evaluates to true, the corresponding 'action' is enforced. Structure is documented below.
Address groups which should be matched against the traffic destination. Maximum number of destination address groups is 10.
References to AddressGroup in networksecurity to populate destAddressGroups.
Policies for referencing.
Selector for a list of AddressGroup in networksecurity to populate destAddressGroups.
Policies for selection.
Fully Qualified Domain Name (FQDN) which should be matched against traffic destination. Maximum number of destination fqdn allowed is 100.
CIDR IP address range. Maximum number of destination CIDR IP ranges allowed is 5000.
Region codes whose IP addresses will be used to match for destination of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of dest region codes allowed is 5000.
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic destination.
Pairs of IP protocols and ports that the rule should match. Structure is documented below.
An optional list of ports to which this rule applies. This field is only applicable for UDP or TCP protocol. Each entry must be either an integer or a range. If not specified, this rule applies to connections through any port.
Address groups which should be matched against the traffic source. Maximum number of source address groups is 10.
Fully Qualified Domain Name (FQDN) which should be matched against traffic source. Maximum number of source fqdn allowed is 100.
CIDR IP address range. Maximum number of source CIDR IP ranges allowed is 5000.
Region codes whose IP addresses will be used to match for source of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of source region codes allowed is 5000.
List of secure tag values, which should be matched at the source of the traffic. For INGRESS rule, if all the srcSecureTag are INEFFECTIVE, and there is no srcIpRange, this rule will be ignored. Maximum number of source tag values allowed is 256. Structure is documented below.
Reference to a TagValue in tags to populate name.
Policies for referencing.
Selector for a TagValue in tags to populate name.
Policies for selection.
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic source.
A list of network resource URLs to which this rule applies. This field allows you to control which network's VMs get this rule. If this field is left blank, all VMs within the organization will receive the rule.
A list of secure tags that controls which instances the firewall rule applies to. If targetSecureTag are specified, then the firewall rule applies only to instances in the VPC network that have one of those EFFECTIVE secure tags, if all the targetSecureTag are in INEFFECTIVE state, then this rule will be ignored. targetSecureTag may not be set at the same time as targetServiceAccounts. If neither targetServiceAccounts nor targetSecureTag are specified, the firewall rule applies to all instances on the specified network. Maximum number of target secure tags allowed is 256. Structure is documented below.
Reference to a TagValue in tags to populate name.
Policies for referencing.
Selector for a TagValue in tags to populate name.
Policies for selection.
A list of service accounts indicating the sets of instances that are applied with this rule.
THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md
WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.
FirewallPolicyRuleStatus defines the observed state of FirewallPolicyRule.
(No description available)
A match condition that incoming traffic is evaluated against. If it evaluates to true, the corresponding 'action' is enforced. Structure is documented below.
Address groups which should be matched against the traffic destination. Maximum number of destination address groups is 10.
Fully Qualified Domain Name (FQDN) which should be matched against traffic destination. Maximum number of destination fqdn allowed is 100.
CIDR IP address range. Maximum number of destination CIDR IP ranges allowed is 5000.
Region codes whose IP addresses will be used to match for destination of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of dest region codes allowed is 5000.
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic destination.
Pairs of IP protocols and ports that the rule should match. Structure is documented below.
An optional list of ports to which this rule applies. This field is only applicable for UDP or TCP protocol. Each entry must be either an integer or a range. If not specified, this rule applies to connections through any port.
Address groups which should be matched against the traffic source. Maximum number of source address groups is 10.
Fully Qualified Domain Name (FQDN) which should be matched against traffic source. Maximum number of source fqdn allowed is 100.
CIDR IP address range. Maximum number of source CIDR IP ranges allowed is 5000.
Region codes whose IP addresses will be used to match for source of traffic. Should be specified as 2 letter country code defined as per ISO 3166 alpha-2 country codes. ex."US" Maximum number of source region codes allowed is 5000.
List of secure tag values, which should be matched at the source of the traffic. For INGRESS rule, if all the srcSecureTag are INEFFECTIVE, and there is no srcIpRange, this rule will be ignored. Maximum number of source tag values allowed is 256. Structure is documented below.
Names of Network Threat Intelligence lists. The IPs in these lists will be matched against traffic source.
A list of network resource URLs to which this rule applies. This field allows you to control which network's VMs get this rule. If this field is left blank, all VMs within the organization will receive the rule.
A list of secure tags that controls which instances the firewall rule applies to. If targetSecureTag are specified, then the firewall rule applies only to instances in the VPC network that have one of those EFFECTIVE secure tags, if all the targetSecureTag are in INEFFECTIVE state, then this rule will be ignored. targetSecureTag may not be set at the same time as targetServiceAccounts. If neither targetServiceAccounts nor targetSecureTag are specified, the firewall rule applies to all instances on the specified network. Maximum number of target secure tags allowed is 256. Structure is documented below.
A list of service accounts indicating the sets of instances that are applied with this rule.
Conditions of the resource.