yandex_sws_security_profile (Data Source)
- Example usage
- Schema
- Optional
- Read-Only
- Nested Schema for security_rule
- Nested Schema for security_rule.rule_condition
- Nested Schema for security_rule.rule_condition.condition
- Nested Schema for security_rule.rule_condition.condition.authority
- Nested Schema for security_rule.rule_condition.condition.source_ip.authorities
- Nested Schema for security_rule.rule_condition.condition.headers
- Nested Schema for security_rule.rule_condition.condition.source_ip.value
- Nested Schema for security_rule.rule_condition.condition.http_method
- Nested Schema for security_rule.rule_condition.condition.source_ip.http_methods
- Nested Schema for security_rule.rule_condition.condition.request_uri
- Nested Schema for security_rule.rule_condition.condition.source_ip.path
- Nested Schema for security_rule.rule_condition.condition.source_ip.queries
- Nested Schema for security_rule.rule_condition.condition.source_ip.queries.value
- Nested Schema for security_rule.rule_condition.condition.source_ip
- Nested Schema for security_rule.rule_condition.condition.source_ip.geo_ip_match
- Nested Schema for security_rule.rule_condition.condition.source_ip.geo_ip_not_match
- Nested Schema for security_rule.rule_condition.condition.source_ip.ip_ranges_match
- Nested Schema for security_rule.rule_condition.condition.source_ip.ip_ranges_not_match
- Nested Schema for security_rule.smart_protection
- Nested Schema for security_rule.smart_protection.condition
- Nested Schema for security_rule.smart_protection.condition.authority
- Nested Schema for security_rule.smart_protection.condition.source_ip.authorities
- Nested Schema for security_rule.smart_protection.condition.headers
- Nested Schema for security_rule.smart_protection.condition.source_ip.value
- Nested Schema for security_rule.smart_protection.condition.http_method
- Nested Schema for security_rule.smart_protection.condition.source_ip.http_methods
- Nested Schema for security_rule.smart_protection.condition.request_uri
- Nested Schema for security_rule.smart_protection.condition.source_ip.path
- Nested Schema for security_rule.smart_protection.condition.source_ip.queries
- Nested Schema for security_rule.smart_protection.condition.source_ip.queries.value
- Nested Schema for security_rule.smart_protection.condition.source_ip
- Nested Schema for security_rule.smart_protection.condition.source_ip.geo_ip_match
- Nested Schema for security_rule.smart_protection.condition.source_ip.geo_ip_not_match
- Nested Schema for security_rule.smart_protection.condition.source_ip.ip_ranges_match
- Nested Schema for security_rule.smart_protection.condition.source_ip.ip_ranges_not_match
- Nested Schema for security_rule.waf
- Nested Schema for security_rule.waf.condition
- Nested Schema for security_rule.waf.condition.authority
- Nested Schema for security_rule.waf.condition.source_ip.authorities
- Nested Schema for security_rule.waf.condition.headers
- Nested Schema for security_rule.waf.condition.source_ip.value
- Nested Schema for security_rule.waf.condition.http_method
- Nested Schema for security_rule.waf.condition.source_ip.http_methods
- Nested Schema for security_rule.waf.condition.request_uri
- Nested Schema for security_rule.waf.condition.source_ip.path
- Nested Schema for security_rule.waf.condition.source_ip.queries
- Nested Schema for security_rule.waf.condition.source_ip.queries.value
- Nested Schema for security_rule.waf.condition.source_ip
- Nested Schema for security_rule.waf.condition.source_ip.geo_ip_match
- Nested Schema for security_rule.waf.condition.source_ip.geo_ip_not_match
- Nested Schema for security_rule.waf.condition.source_ip.ip_ranges_match
- Nested Schema for security_rule.waf.condition.source_ip.ip_ranges_not_match
Get information about SecurityProfile. For more information, see the official documentation.
This data source is used to define SecurityProfile that can be used by other resources.
~> One of security_profile_id
or name
should be specified.
Example usage
//
// Get information about existing SWS Security Profile.
//
data "yandex_sws_security_profile" "by-id" {
security_profile_id = yandex_sws_security_profile.my-profile.id
}
data "yandex_sws_security_profile" "by-name" {
name = yandex_sws_security_profile.my-profile.name
}
Schema
Optional
cloud_id
(String) TheCloud ID
which resource belongs to. If it is not provided, the default providercloud-id
is used.folder_id
(String) The folder identifier that resource belongs to. If it is not provided, the default providerfolder-id
is used.name
(String) The resource name.security_profile_id
(String) ID of the security profile.
Read-Only
advanced_rate_limiter_profile_id
(String) Advanced rate limiter profile ID to use with this security profile. Set empty to use default.captcha_id
(String) Captcha ID to use with this security profile. Set empty to use default.created_at
(String) The creation timestamp of the resource.default_action
(String) Action to perform if none of rules matched. Possible values:ALLOW
orDENY
.description
(String) The resource description.id
(String) The ID of this resource.labels
(Map of String) A set of key/value label pairs which assigned to resource.security_rule
(List of Object) (see below for nested schema)
security_rule
Nested Schema for Read-Only:
-
description
(String) Optional description of the rule. 0-512 characters long. -
dry_run
(Boolean) This mode allows you to test your security profile or a single rule. -
name
(String) Name of the rule. The name is unique within the security profile. 1-50 characters long. -
priority
(Number) Determines the priority for checking the incoming traffic. -
rule_condition
(Block List, Max: 1) Rule actions, see Rule actions. (see below for nested schema) -
smart_protection
(Block List, Max: 1) Smart Protection rule, see Smart Protection rules. (see below for nested schema) -
waf
(Block List, Max: 1) Web Application Firewall (WAF) rule, see WAF rules. (see below for nested schema)
security_rule.rule_condition
Nested Schema for Read-Only:
-
action
(String) Action to perform if this rule matched. Possible values:ALLOW
orDENY
. -
condition
(Block List, Max: 1) The condition for matching the rule. You can find all possibilities of condition in gRPC specs . (see below for nested schema)
security_rule.rule_condition.condition
Nested Schema for Read-Only:
authority
(List of Object) (see below for nested schema)headers
(List of Object) (see below for nested schema)http_method
(List of Object) (see below for nested schema)request_uri
(List of Object) (see below for nested schema)source_ip
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.authority
Nested Schema for Read-Only:
authorities
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.source_ip.authorities
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.rule_condition.condition.headers
Nested Schema for Read-Only:
name
(String)value
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.source_ip.value
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.rule_condition.condition.http_method
Nested Schema for Read-Only:
http_methods
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.source_ip.http_methods
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.rule_condition.condition.request_uri
Nested Schema for Read-Only:
path
(List of Object) (see below for nested schema)queries
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.source_ip.path
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.rule_condition.condition.source_ip.queries
Nested Schema for Read-Only:
key
(String)value
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.source_ip.queries.value
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.rule_condition.condition.source_ip
Nested Schema for Read-Only:
geo_ip_match
(List of Object) (see below for nested schema)geo_ip_not_match
(List of Object) (see below for nested schema)ip_ranges_match
(List of Object) (see below for nested schema)ip_ranges_not_match
(List of Object) (see below for nested schema)
security_rule.rule_condition.condition.source_ip.geo_ip_match
Nested Schema for Read-Only:
locations
(List of String)
security_rule.rule_condition.condition.source_ip.geo_ip_not_match
Nested Schema for Read-Only:
locations
(List of String)
security_rule.rule_condition.condition.source_ip.ip_ranges_match
Nested Schema for Read-Only:
ip_ranges
(List of String)
security_rule.rule_condition.condition.source_ip.ip_ranges_not_match
Nested Schema for Read-Only:
ip_ranges
(List of String)
security_rule.smart_protection
Nested Schema for Read-Only:
-
condition
(Block List, Max: 1) The condition for matching the rule. You can find all possibilities of condition in gRPC specs . (see below for nested schema) -
mode
(String) Mode of protection. Possible values:FULL
(full protection means that the traffic will be checked based on ML models and behavioral analysis, with suspicious requests being sent to SmartCaptcha) orAPI
(API protection means checking the traffic based on ML models and behavioral analysis without sending suspicious requests to SmartCaptcha. The suspicious requests will be blocked).
security_rule.smart_protection.condition
Nested Schema for Read-Only:
authority
(List of Object) (see below for nested schema)headers
(List of Object) (see below for nested schema)http_method
(List of Object) (see below for nested schema)request_uri
(List of Object) (see below for nested schema)source_ip
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.authority
Nested Schema for Read-Only:
authorities
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.source_ip.authorities
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.smart_protection.condition.headers
Nested Schema for Read-Only:
name
(String)value
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.source_ip.value
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.smart_protection.condition.http_method
Nested Schema for Read-Only:
http_methods
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.source_ip.http_methods
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.smart_protection.condition.request_uri
Nested Schema for Read-Only:
path
(List of Object) (see below for nested schema)queries
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.source_ip.path
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.smart_protection.condition.source_ip.queries
Nested Schema for Read-Only:
key
(String)value
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.source_ip.queries.value
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.smart_protection.condition.source_ip
Nested Schema for Read-Only:
geo_ip_match
(List of Object) (see below for nested schema)geo_ip_not_match
(List of Object) (see below for nested schema)ip_ranges_match
(List of Object) (see below for nested schema)ip_ranges_not_match
(List of Object) (see below for nested schema)
security_rule.smart_protection.condition.source_ip.geo_ip_match
Nested Schema for Read-Only:
locations
(List of String)
security_rule.smart_protection.condition.source_ip.geo_ip_not_match
Nested Schema for Read-Only:
locations
(List of String)
security_rule.smart_protection.condition.source_ip.ip_ranges_match
Nested Schema for Read-Only:
ip_ranges
(List of String)
security_rule.smart_protection.condition.source_ip.ip_ranges_not_match
Nested Schema for Read-Only:
ip_ranges
(List of String)
security_rule.waf
Nested Schema for Read-Only:
-
condition
(Block List, Max: 1) The condition for matching the rule. You can find all possibilities of condition in gRPC specs . (see below for nested schema) -
mode
(String) Mode of protection. Possible values:FULL
(full protection means that the traffic will be checked based on ML models and behavioral analysis, with suspicious requests being sent to SmartCaptcha) orAPI
(API protection means checking the traffic based on ML models and behavioral analysis without sending suspicious requests to SmartCaptcha. The suspicious requests will be blocked). -
waf_profile_id
(String) ID of WAF profile to use in this rule.
security_rule.waf.condition
Nested Schema for Read-Only:
authority
(List of Object) (see below for nested schema)headers
(List of Object) (see below for nested schema)http_method
(List of Object) (see below for nested schema)request_uri
(List of Object) (see below for nested schema)source_ip
(List of Object) (see below for nested schema)
security_rule.waf.condition.authority
Nested Schema for Read-Only:
authorities
(List of Object) (see below for nested schema)
security_rule.waf.condition.source_ip.authorities
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.waf.condition.headers
Nested Schema for Read-Only:
name
(String)value
(List of Object) (see below for nested schema)
security_rule.waf.condition.source_ip.value
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.waf.condition.http_method
Nested Schema for Read-Only:
http_methods
(List of Object) (see below for nested schema)
security_rule.waf.condition.source_ip.http_methods
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.waf.condition.request_uri
Nested Schema for Read-Only:
path
(List of Object) (see below for nested schema)queries
(List of Object) (see below for nested schema)
security_rule.waf.condition.source_ip.path
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.waf.condition.source_ip.queries
Nested Schema for Read-Only:
key
(String)value
(List of Object) (see below for nested schema)
security_rule.waf.condition.source_ip.queries.value
Nested Schema for Read-Only:
exact_match
(String)exact_not_match
(String)pire_regex_match
(String)pire_regex_not_match
(String)prefix_match
(String)prefix_not_match
(String)
security_rule.waf.condition.source_ip
Nested Schema for Read-Only:
geo_ip_match
(List of Object) (see below for nested schema)geo_ip_not_match
(List of Object) (see below for nested schema)ip_ranges_match
(List of Object) (see below for nested schema)ip_ranges_not_match
(List of Object) (see below for nested schema)
security_rule.waf.condition.source_ip.geo_ip_match
Nested Schema for Read-Only:
locations
(List of String)
security_rule.waf.condition.source_ip.geo_ip_not_match
Nested Schema for Read-Only:
locations
(List of String)
security_rule.waf.condition.source_ip.ip_ranges_match
Nested Schema for Read-Only:
ip_ranges
(List of String)
security_rule.waf.condition.source_ip.ip_ranges_not_match
Nested Schema for Read-Only:
ip_ranges
(List of String)