Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Smart Web Security
  • Getting started
    • Overview
    • Security profiles
    • WAF
    • ARL (request limit)
    • Rules
    • Conditions
    • Lists
    • Managing bot traffic
    • Protecting domains
    • Response templates
    • Logging
    • Quotas and limits
  • Access management
  • Pricing policy
  • Terraform reference
    • API authentication
      • Overview
        • Overview
          • Overview
          • Get
          • List
          • Create
          • Update
          • Delete
  • Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • HTTP request
  • Path parameters
  • Body parameters
  • HttpBackend
  • Target
  • SessionAffinity
  • ConnectionSessionAffinity
  • HeaderSessionAffinity
  • CookieSessionAffinity
  • TlsListener
  • HttpListener
  • SolidWafSettings
  • RateLimit
  • Response
  • Status
  1. API reference
  2. REST
  3. Smart Web Security Load Balancer API
  4. Domain
  5. Create

Smart Web Security Load Balancer API, REST: Domain.Create

Written by
Yandex Cloud
Updated at September 21, 2026
View in Markdown
  • HTTP request
  • Path parameters
  • Body parameters
  • HttpBackend
  • Target
  • SessionAffinity
  • ConnectionSessionAffinity
  • HeaderSessionAffinity
  • CookieSessionAffinity
  • TlsListener
  • HttpListener
  • SolidWafSettings
  • RateLimit
  • Response
  • Status

Creates a domain in the specified load balancer.

HTTP requestHTTP request

POST https://smartwebsecurity.api.cloud.yandex.net/smartwebsecurity/v1/loadBalancers/{loadBalancerId}/domains

Path parametersPath parameters

Field

Description

loadBalancerId

string

Required field. ID of the Load balancer that the domain belongs to.

Body parametersBody parameters

{
  "name": "string",
  "serverName": "string",
  "description": "string",
  "securityProfileId": "string",
  "httpBackend": {
    "targets": [
      {
        "ipAddress": "string",
        "description": "string",
        "port": "string"
      }
    ],
    "useHttp2": "boolean",
    "useTls": "boolean",
    "sni": "string",
    "trustedCaBytes": "string",
    "timeout": "string",
    "idleTimeout": "string",
    "sessionAffinity": {
      // Includes only one of the fields `connection`, `header`, `cookie`
      "connection": {
        "sourceIp": "boolean"
      },
      "header": {
        "headerName": "string"
      },
      "cookie": {
        "name": "string",
        "ttl": "string",
        "path": "string"
      }
      // end of the list of possible fields
    }
  },
  "tlsListener": {
    "enabled": "boolean",
    "certificateId": "string",
    "port": "string",
    "enableHttp1": "boolean"
  },
  "httpListener": {
    "enabled": "boolean",
    "redirectToHttps": "boolean",
    "port": "string"
  },
  "solidWafSettings": {
    "solidWafProfileId": "string",
    "sessionAffinity": {
      // Includes only one of the fields `connection`, `header`, `cookie`
      "connection": {
        "sourceIp": "boolean"
      },
      "header": {
        "headerName": "string"
      },
      "cookie": {
        "name": "string",
        "ttl": "string",
        "path": "string"
      }
      // end of the list of possible fields
    },
    "webAppId": "string"
  },
  "rateLimit": {
    "allRequestsPerSecond": "string",
    "requestsPerIpPerSecond": "string"
  }
}

Field

Description

name

string

Unique name of domain within the balancer.
Will be used for monitoring naming and error messages.
If empty, will be generated automaticly from server_name.

Value must match the regular expression |[a-z][-a-z0-9]{1,56}[a-z0-9].

serverName

string

Required field. Server name or wildcard to be matched against SNI in a TLS connection and authority(host) header.
Wildcards are in the form of ".s.o.m.e".
Allowed: "example.com", "
.example.com".
Not allowed: "..example.com", "*-sub.example.com".

The string length in characters must be 1-255.

description

string

Domain description.

The maximum string length in characters is 512.

securityProfileId

string

Security Profile ID of SmartWebSecurity service.

httpBackend

HttpBackend

Backend settings.

tlsListener

TlsListener

Optional TLS listener settings.

httpListener

HttpListener

Optional plaintext listener settings.

solidWafSettings

SolidWafSettings

Optional Solid WAF settings.

rateLimit

RateLimit

Optional rate limit settings.

HttpBackendHttpBackend

Field

Description

targets[]

Target

List of targets.

The number of elements must be in the range 1-20.

useHttp2

boolean

Enables HTTP2 for upstream requests.
If not set, HTTP 1.1 will be used by default.

useTls

boolean

Enable TLS for upstream requests.

sni

string

SNI string for TLS connections.
Applicable only if use_tls enabled.

The maximum string length in characters is 255. Value must match the regular expression [-.a-z0-9]*.

trustedCaBytes

string

Trusted certificate authority certificates bundle (PEM text).
Applicable only if use_tls enabled.

timeout

string (duration)

Backend timeout. If not set, default is 300 seconds.

idleTimeout

string (duration)

Specifies the idle timeout for the route. If not specified, there is no per-route idle timeout.

sessionAffinity

SessionAffinity

Session affinity.

TargetTarget

Field

Description

ipAddress

string

IPv4 address.

The string length in characters must be 1-40.

description

string

Target description.

The maximum string length in characters is 128.

port

string (int64)

Target port.

Acceptable values are 1 to 65535, inclusive.

SessionAffinitySessionAffinity

Field

Description

connection

ConnectionSessionAffinity

Session affinity based on source IP address.

Includes only one of the fields connection, header, cookie.

header

HeaderSessionAffinity

Session affinity based on an HTTP header.

Includes only one of the fields connection, header, cookie.

cookie

CookieSessionAffinity

Session affinity based on a cookie.

Includes only one of the fields connection, header, cookie.

ConnectionSessionAffinityConnectionSessionAffinity

Field

Description

sourceIp

boolean

IP address.

HeaderSessionAffinityHeaderSessionAffinity

Field

Description

headerName

string

Header name.

The string length in characters must be 1-256.

CookieSessionAffinityCookieSessionAffinity

Field

Description

name

string

Cookie name.

The string length in characters must be 1-256.

ttl

string (duration)

If not set, session cookie will be used (not persisted between browser restarts).

path

string

Optional cookie path.

The string length in characters must be 0-256.

TlsListenerTlsListener

Field

Description

enabled

boolean

Enable TLS listener.

certificateId

string

Certificate ID in the Certificate Manager.

port

string (int64)

Listener port. If value is not set, used 443 by default.

Acceptable values are 0 to 65535, inclusive.

enableHttp1

boolean

Enables HTTP/1.0 and HTTP/1.1 support and disables HTTP/2.

HttpListenerHttpListener

Field

Description

enabled

boolean

Enable http (plaintext) listener.

redirectToHttps

boolean

Automatically redirect from HTTP to HTTPS.
If TlsListener's port is 443 or not set, redirect URL will be "https://<host><path>" and "https://<host>:<port><path>" in other case.

port

string (int64)

Listener port. If value is not set, used 80 by default.

Acceptable values are 0 to 65535, inclusive.

SolidWafSettingsSolidWafSettings

Field

Description

solidWafProfileId

string

ID of the Solid WAF profile.

sessionAffinity

SessionAffinity

Session affinity to analyzers. If not set, ConnectionSessionAffinity will be used.

webAppId

string

ID of the Solid WAF web app.

RateLimitRateLimit

Field

Description

allRequestsPerSecond

string (int64)

Rate limit for all requests.
Defaults:

  • with SolidWaf enabled: 20000 RPS
  • without SolidWaf enabled: unlimited

The minimum value is 0.

requestsPerIpPerSecond

string (int64)

Rate limit for individual IP addresses.
Defaults:

  • with SolidWaf enabled: 1000 RPS
  • without SolidWaf enabled: unlimited

The minimum value is 0.

ResponseResponse

HTTP Code: 200 - OK

{
  "id": "string",
  "description": "string",
  "createdAt": "string",
  "createdBy": "string",
  "modifiedAt": "string",
  "done": "boolean",
  "metadata": "object",
  // Includes only one of the fields `error`, `response`
  "error": {
    "code": "integer",
    "message": "string",
    "details": [
      "object"
    ]
  },
  "response": "object"
  // end of the list of possible fields
}

An Operation resource. For more information, see Operation.

Field

Description

id

string

ID of the operation.

description

string

Description of the operation. 0-256 characters long.

createdAt

string (date-time)

Creation timestamp.

String in RFC3339 text format. The range of possible values is from
0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z, i.e. from 0 to 9 digits for fractions of a second.

To work with values in this field, use the APIs described in the
Protocol Buffers reference.
In some languages, built-in datetime utilities do not support nanosecond precision (9 digits).

createdBy

string

ID of the user or service account who initiated the operation.

modifiedAt

string (date-time)

The time when the Operation resource was last modified.

String in RFC3339 text format. The range of possible values is from
0001-01-01T00:00:00Z to 9999-12-31T23:59:59.999999999Z, i.e. from 0 to 9 digits for fractions of a second.

To work with values in this field, use the APIs described in the
Protocol Buffers reference.
In some languages, built-in datetime utilities do not support nanosecond precision (9 digits).

done

boolean

If the value is false, it means the operation is still in progress.
If true, the operation is completed, and either error or response is available.

metadata

object

Service-specific metadata associated with the operation.
It typically contains the ID of the target resource that the operation is performed on.
Any method that returns a long-running operation should document the metadata type, if any.

error

Status

The error result of the operation in case of failure or cancellation.

Includes only one of the fields error, response.

The operation result.
If done == false and there was no failure detected, neither error nor response is set.
If done == false and there was a failure detected, error is set.
If done == true, exactly one of error or response is set.

response

object

The normal response of the operation in case of success.
If the original method returns no data on success, such as Delete,
the response is google.protobuf.Empty.
If the original method is the standard Create/Update,
the response should be the target resource of the operation.
Any method that returns a long-running operation should document the response type, if any.

Includes only one of the fields error, response.

The operation result.
If done == false and there was no failure detected, neither error nor response is set.
If done == false and there was a failure detected, error is set.
If done == true, exactly one of error or response is set.

StatusStatus

The error result of the operation in case of failure or cancellation.

Field

Description

code

integer (int32)

Error code. An enum value of google.rpc.Code.

message

string

An error message.

details[]

object

A list of messages that carry the error details.

Was the article helpful?

Previous
List
Next
Update
© 2026 Direct Cursus Technology L.L.C.