添加安全组规则
Headers
Authorization: OAuth the-session-uuidBody
{
"params": {
"rules": [
{
"type": "Ingress",
"state": "Enabled",
"description": "test",
"remoteSecurityGroupUuid": "7d4337c2b18339ffb6f5d1023fc2ea42",
"ipVersion": 4,
"protocol": "TCP",
"srcIpRange": "10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24",
"dstIpRange": "10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24",
"dstPortRange": "1000,1001,1002-1005,1008",
"action": "ACCEPT"
}
],
"priority": -1
},
"systemTags": [],
"userTags": []
}上述示例中systemTags、userTags字段可以省略。列出是为了表示body中可以包含这两个字段。
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8"
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c"
-X POST -d '{"params":{"rules":[{"type":"Ingress","state":"Enabled","description":"test","remoteSecurityGroupUuid":"7d4337c2b18339ffb6f5d1023fc2ea42","ipVersion":4,"protocol":"TCP","srcIpRange":"10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24","dstIpRange":"10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24","dstPortRange":"1000,1001,1002-1005,1008","action":"ACCEPT"}],"priority":-1}}'
http://localhost:8080/zstack/v1/security-groups/00fdf47ec62b316a8f17c80d0ee59a01/rules参数列表
| 名字 | 类型 | 位置 | 描述 | 可选值 | 起始版本 |
|---|---|---|---|---|---|
| securityGroupUuid | String | url | 安全组UUID | 0.6 | |
| rules | List | body(包含在params结构中) | 安全组中的规则 | 0.6 | |
| remoteSecurityGroupUuids (可选) | List | body(包含在params结构中) | 应用组间策略的远端安全组UUID | 2.1 | |
| priority(可选) | Integer | body(包含在params结构中) | 规则优先级 | 4.7.21 | |
| systemTags (可选) | List | body | 系统标签 | 0.6 | |
| userTags (可选) | List | body | 用户标签 | 0.6 |
API返回
返回示例
{
"inventory": {
"uuid": "5949aece9cd64d5a939d6dc5e2c1f327",
"name": "web",
"description": "for test",
"state": "Enabled",
"createDate": "Sep 22, 2017 12:24:11 PM",
"lastOpDate": "Sep 22, 2017 12:24:11 PM",
"internalId": 0
}
}| 名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
| success | boolean | 0.6 | |
| error | ErrorCode | 错误码,若不为null,则表示操作失败, 操作成功时该字段为null。 详情参考error | 0.6 |
| inventory | SecurityGroupInventory | 详情参考inventory | 0.6 |
error
| 名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
| code | String | 错误码号,错误的全局唯一标识,例如SYS.1000, HOST.1001 | 0.6 |
| description | String | 错误的概要描述 | 0.6 |
| details | String | 错误的详细信息 | 0.6 |
| elaboration | String | 保留字段,默认为null | 0.6 |
| opaque | LinkedHashMap | 保留字段,默认为null | 0.6 |
| cause | ErrorCode | 根错误,引发当前错误的源错误,若无原错误,该字段为null | 0.6 |
inventory
| 名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
| uuid | String | 资源的UUID,唯一标示该资源 | 0.6 |
| name | String | 资源名称 | 0.6 |
| description | String | 资源的详细描述 | 0.6 |
| state | String | 0.6 | |
| ipVersion | Integer | ip协议号 | 3.1.0 |
| createDate | Timestamp | 创建时间 | 0.6 |
| lastOpDate | Timestamp | 最后一次修改时间 | 0.6 |
| attachedL3NetworkUuids | Set | 0.6 | |
| rules | List | 详情参考rules | 0.6 |
rules
名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
uuid | String | 资源的UUID,唯一标示该资源 | 0.6 |
securityGroupUuid | String | 安全组UUID | 0.6 |
type | String | 流量类型 | 0.6 |
ipVersion | Integer | ip协议号 | 3.1.0 |
protocol | String | 流量协议类型 | 0.6 |
state | String | 规则的可用状态 | 0.6 |
priority | Integer | 规则优先级 | 4.7.21 |
description | String | 规则描述 | 4.7.21 |
srcIpRange | String | 源IP范围 | 4.7.21 |
dstIpRange | String | 目的IP范围 | 4.7.21 |
srcPortRange | String | 源端口范围,当前版本未实现 | 4.7.21 |
dstPortRange | String | 目的端口范围 | 4.7.21 |
action | String | 规则的默认动作 | 4.7.21 |
remoteSecurityGroupUuid | String |
| 0.6 |
allowedCidr | String | 允许的CIDR,根据流量类型的不同,允许的CIDR有不同的含义- 如果流量类型是Ingress,允许的CIDR是允许访问虚拟机网卡的源CIDR
| 0.6 |
startPort | Integer |
| 0.6 |
endPort | Integer |
| 0.6 |
createDate | Timestamp | 创建时间 | 0.6 |
lastOpDate | Timestamp | 最后一次修改时间 | 0.6 |
SDK示例
Java SDK
AddSecurityGroupRuleAction action = new AddSecurityGroupRuleAction();
action.securityGroupUuid = "00fdf47ec62b316a8f17c80d0ee59a01";
action.rules = asList([type:Ingress, state:Enabled, description:test, remoteSecurityGroupUuid:7d4337c2b18339ffb6f5d1023fc2ea42, ipVersion:4, protocol:TCP, srcIpRange:10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24, dstIpRange:10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24, dstPortRange:1000,1001,1002-1005,1008, action:ACCEPT]);
action.priority = -1;
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
AddSecurityGroupRuleAction.Result res = action.call();
Python SDK
AddSecurityGroupRuleAction action = AddSecurityGroupRuleAction()
action.securityGroupUuid = "00fdf47ec62b316a8f17c80d0ee59a01"
action.rules = [[type:Ingress, state:Enabled, description:test, remoteSecurityGroupUuid:7d4337c2b18339ffb6f5d1023fc2ea42, ipVersion:4, protocol:TCP, srcIpRange:10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24, dstIpRange:10.0.0.1,10.0.0.2-10.0.0.200,10.1.1.0/24, dstPortRange:1000,1001,1002-1005,1008, action:ACCEPT]]
action.priority = -1
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
AddSecurityGroupRuleAction.Result res = action.call()