RouterNATRouterNAT is the Schema for the RouterNATs API. A NAT service created in a router.
TypeMR
Providerprovider-gcp-compute
Groupcompute.gcp.m.upbound.io
Scopenamespaced
Versionv1beta1

1apiVersion: compute.gcp.m.upbound.io/v1beta1

2kind: RouterNAT

kind
string
metadata
object
spec
object

RouterNATSpec defines the desired state of RouterNAT

forProvider
required
object

(No description available)

array

A list of URLs of the IP resources to be drained. These IPs must be valid static external IPs that have been assigned to the NAT.

array

Specifies the endpoint Types supported by the NAT Gateway. Supported values include: ENDPOINT_TYPE_VM, ENDPOINT_TYPE_SWG, ENDPOINT_TYPE_MANAGED_PROXY_LB.

array

Self-links of NAT IPs to be used as initial value for creation alongside a RouterNatAddress resource. Conflicts with natIps and drainNatIps. Only valid if natIpAllocateOption is set to MANUAL_ONLY.

logConfig
object

Configuration for logging on NAT Structure is documented below.

enable
boolean
filter
string
array

One or more subnetwork NAT configurations whose traffic should be translated by NAT64 Gateway. Only used if source_subnetwork_ip_ranges_to_nat64 is set to LIST_OF_IPV6_SUBNETWORKS Structure is documented below.

name
string
natIps
array

Self-links of NAT IPs. Only valid if natIpAllocateOption is set to MANUAL_ONLY. If this field is used alongside with a count created list of address resources google_compute_address.foobar.*.self_link, the access level resource for the address resource must have a lifecycle block with create_before_destroy = true so the number of resources can be increased/decreased without triggering the resourceInUseByAnotherResource error.

array

References to Address in compute to populate natIps.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a list of Address in compute to populate natIps.

namespace
string
policy
object

Policies for selection.

resolve
string
project
string
region
required
string
router
string
routerRef
object

Reference to a Router in compute to populate router.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a Router in compute to populate router.

namespace
string
policy
object

Policies for selection.

resolve
string
rules
array

A list of rules associated with this NAT. Structure is documented below.

action
object

The action to be enforced for traffic that matches this rule. Structure is documented below.

array

A list of URLs of the IP resources used for this NAT rule. These IP addresses must be valid static external IP addresses assigned to the project. This field is used for public NAT.

array

References to Address in compute to populate sourceNatActiveIps.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a list of Address in compute to populate sourceNatActiveIps.

namespace
string
policy
object

Policies for selection.

resolve
string
array

A list of URLs of the subnetworks used as source ranges for this NAT Rule. These subnetworks must have purpose set to PRIVATE_NAT. This field is used for private NAT.

array

References to Subnetwork in compute to populate sourceNatActiveRanges.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a list of Subnetwork in compute to populate sourceNatActiveRanges.

namespace
string
policy
object

Policies for selection.

resolve
string
array

A list of URLs of the IP resources to be drained. These IPs must be valid static external IPs that have been assigned to the NAT. These IPs should be used for updating/patching a NAT rule only. This field is used for public NAT.

array

A list of URLs of subnetworks representing source ranges to be drained. This is only supported on patch/update, and these subnetworks must have previously been used as active ranges in this NAT Rule. This field is used for private NAT.

match
string
array

One or more subnetwork NAT configurations. Only used if source_subnetwork_ip_ranges_to_nat is set to LIST_OF_SUBNETWORKS Structure is documented below.

name
string
nameRef
object

Reference to a Subnetwork in compute to populate name.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a Subnetwork in compute to populate name.

namespace
string
policy
object

Policies for selection.

resolve
string
array

List of the secondary ranges of the subnetwork that are allowed to use NAT. This can be populated only if LIST_OF_SECONDARY_IP_RANGES is one of the values in sourceIpRangesToNat

array

List of options for which source IPs in the subnetwork should have NAT enabled. Supported values include: ALL_IP_RANGES, LIST_OF_SECONDARY_IP_RANGES, PRIMARY_IP_RANGE.

type
string
object

THIS IS A BETA FIELD. It will be honored unless the Management Policies feature flag is disabled. InitProvider holds the same fields as ForProvider, with the exception of Identifier and other resource reference fields. The fields that are in InitProvider are merged into ForProvider when the resource is created. The same fields are also added to the terraform ignore_changes hook, to avoid updating them after creation. This is useful for fields that are required on creation, but we do not desire to update them after creation, for example because of an external controller is managing them, like an autoscaler.

array

A list of URLs of the IP resources to be drained. These IPs must be valid static external IPs that have been assigned to the NAT.

array

Specifies the endpoint Types supported by the NAT Gateway. Supported values include: ENDPOINT_TYPE_VM, ENDPOINT_TYPE_SWG, ENDPOINT_TYPE_MANAGED_PROXY_LB.

array

Self-links of NAT IPs to be used as initial value for creation alongside a RouterNatAddress resource. Conflicts with natIps and drainNatIps. Only valid if natIpAllocateOption is set to MANUAL_ONLY.

logConfig
object

Configuration for logging on NAT Structure is documented below.

enable
boolean
filter
string
array

One or more subnetwork NAT configurations whose traffic should be translated by NAT64 Gateway. Only used if source_subnetwork_ip_ranges_to_nat64 is set to LIST_OF_IPV6_SUBNETWORKS Structure is documented below.

name
string
natIps
array

Self-links of NAT IPs. Only valid if natIpAllocateOption is set to MANUAL_ONLY. If this field is used alongside with a count created list of address resources google_compute_address.foobar.*.self_link, the access level resource for the address resource must have a lifecycle block with create_before_destroy = true so the number of resources can be increased/decreased without triggering the resourceInUseByAnotherResource error.

array

References to Address in compute to populate natIps.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a list of Address in compute to populate natIps.

namespace
string
policy
object

Policies for selection.

resolve
string
project
string
rules
array

A list of rules associated with this NAT. Structure is documented below.

action
object

The action to be enforced for traffic that matches this rule. Structure is documented below.

array

A list of URLs of the IP resources used for this NAT rule. These IP addresses must be valid static external IP addresses assigned to the project. This field is used for public NAT.

array

References to Address in compute to populate sourceNatActiveIps.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a list of Address in compute to populate sourceNatActiveIps.

namespace
string
policy
object

Policies for selection.

resolve
string
array

A list of URLs of the subnetworks used as source ranges for this NAT Rule. These subnetworks must have purpose set to PRIVATE_NAT. This field is used for private NAT.

array

References to Subnetwork in compute to populate sourceNatActiveRanges.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a list of Subnetwork in compute to populate sourceNatActiveRanges.

namespace
string
policy
object

Policies for selection.

resolve
string
array

A list of URLs of the IP resources to be drained. These IPs must be valid static external IPs that have been assigned to the NAT. These IPs should be used for updating/patching a NAT rule only. This field is used for public NAT.

array

A list of URLs of subnetworks representing source ranges to be drained. This is only supported on patch/update, and these subnetworks must have previously been used as active ranges in this NAT Rule. This field is used for private NAT.

match
string
array

One or more subnetwork NAT configurations. Only used if source_subnetwork_ip_ranges_to_nat is set to LIST_OF_SUBNETWORKS Structure is documented below.

name
string
nameRef
object

Reference to a Subnetwork in compute to populate name.

name
required
string
namespace
string
policy
object

Policies for referencing.

resolve
string
object

Selector for a Subnetwork in compute to populate name.

namespace
string
policy
object

Policies for selection.

resolve
string
array

List of the secondary ranges of the subnetwork that are allowed to use NAT. This can be populated only if LIST_OF_SECONDARY_IP_RANGES is one of the values in sourceIpRangesToNat

array

List of options for which source IPs in the subnetwork should have NAT enabled. Supported values include: ALL_IP_RANGES, LIST_OF_SECONDARY_IP_RANGES, PRIMARY_IP_RANGE.

type
string
array

THIS IS A BETA FIELD. It is on by default but can be opted out through a Crossplane feature flag. ManagementPolicies specify the array of actions Crossplane is allowed to take on the managed and external resources. See the design doc for more information: https://github.com/crossplane/crossplane/blob/499895a25d1a1a0ba1604944ef98ac7a1a71f197/design/design-doc-observe-only-resources.md?plain=1#L223 and this one: https://github.com/crossplane/crossplane/blob/444267e84783136daa93568b364a5f01228cacbe/design/one-pager-ignore-changes.md

object

ProviderConfigReference specifies how the provider that will be used to create, observe, update, and delete this managed resource should be configured.

kind
required
string
name
required
string
object

WriteConnectionSecretToReference specifies the namespace and name of a Secret to which any connection details for this managed resource should be written. Connection details frequently include the endpoint, username, and password required to connect to the managed resource.

name
required
string
status
object

RouterNATStatus defines the observed state of RouterNAT.

object

(No description available)

array

A list of URLs of the IP resources to be drained. These IPs must be valid static external IPs that have been assigned to the NAT.

array

Specifies the endpoint Types supported by the NAT Gateway. Supported values include: ENDPOINT_TYPE_VM, ENDPOINT_TYPE_SWG, ENDPOINT_TYPE_MANAGED_PROXY_LB.

id
string
array

Self-links of NAT IPs to be used as initial value for creation alongside a RouterNatAddress resource. Conflicts with natIps and drainNatIps. Only valid if natIpAllocateOption is set to MANUAL_ONLY.

logConfig
object

Configuration for logging on NAT Structure is documented below.

enable
boolean
filter
string
array

One or more subnetwork NAT configurations whose traffic should be translated by NAT64 Gateway. Only used if source_subnetwork_ip_ranges_to_nat64 is set to LIST_OF_IPV6_SUBNETWORKS Structure is documented below.

name
string
natIps
array

Self-links of NAT IPs. Only valid if natIpAllocateOption is set to MANUAL_ONLY. If this field is used alongside with a count created list of address resources google_compute_address.foobar.*.self_link, the access level resource for the address resource must have a lifecycle block with create_before_destroy = true so the number of resources can be increased/decreased without triggering the resourceInUseByAnotherResource error.

project
string
region
string
router
string
rules
array

A list of rules associated with this NAT. Structure is documented below.

action
object

The action to be enforced for traffic that matches this rule. Structure is documented below.

array

A list of URLs of the IP resources used for this NAT rule. These IP addresses must be valid static external IP addresses assigned to the project. This field is used for public NAT.

array

A list of URLs of the subnetworks used as source ranges for this NAT Rule. These subnetworks must have purpose set to PRIVATE_NAT. This field is used for private NAT.

array

A list of URLs of the IP resources to be drained. These IPs must be valid static external IPs that have been assigned to the NAT. These IPs should be used for updating/patching a NAT rule only. This field is used for public NAT.

array

A list of URLs of subnetworks representing source ranges to be drained. This is only supported on patch/update, and these subnetworks must have previously been used as active ranges in this NAT Rule. This field is used for private NAT.

match
string
array

One or more subnetwork NAT configurations. Only used if source_subnetwork_ip_ranges_to_nat is set to LIST_OF_SUBNETWORKS Structure is documented below.

name
string
array

List of the secondary ranges of the subnetwork that are allowed to use NAT. This can be populated only if LIST_OF_SECONDARY_IP_RANGES is one of the values in sourceIpRangesToNat

array

List of options for which source IPs in the subnetwork should have NAT enabled. Supported values include: ALL_IP_RANGES, LIST_OF_SECONDARY_IP_RANGES, PRIMARY_IP_RANGE.

type
string
array

Conditions of the resource.

lastTransitionTime
required
string
message
string
reason
required
string
status
required
string
type
required
string