修改安全组规则
Headers
Authorization: OAuth the-session-uuidBody
{
"changeSecurityGroupRule": {
"description": "test",
"remoteSecurityGroupUuid": "bd2dcc93fbd73999bf920aeaab3c9e4e",
"action": "DROP",
"state": "Enabled",
"priority": 1,
"protocol": "TCP",
"srcIpRange": "1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10",
"dstPortRange": "1001,2000-2023,6001"
},
"systemTags": [],
"userTags": []
}上述示例中systemTags、userTags字段可以省略。列出是为了表示body中可以包含这两个字段。
Curl示例
curl -H "Content-Type: application/json;charset=UTF-8"
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c"
-X PUT -d '{"changeSecurityGroupRule":{"description":"test","remoteSecurityGroupUuid":"bd2dcc93fbd73999bf920aeaab3c9e4e","action":"DROP","state":"Enabled","priority":1,"protocol":"TCP","srcIpRange":"1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10","dstPortRange":"1001,2000-2023,6001"}}'
http://localhost:8080/zstack/v1/security-groups/85a1d77188d836eab47b34e7129fb5fb/actions参数列表
名字 | 类型 | 位置 | 描述 | 可选值 | 起始版本 |
|---|---|---|---|---|---|
uuid | String | url | 安全组规则的UUID,唯一标示该资源 |
| 4.7.21 |
description(可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的描述 |
| 4.7.21 |
remoteSecurityGroupUuid (可选) | String | body(包含在changeSecurityGroupState结构中) | 应用组间策略的远端安全组UUID | enabledisable | 4.7.21 |
action (可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的默认动作 |
| 4.7.21 |
state (可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的状态 |
| 4.7.21 |
priority (可选) | Integer | body(包含在changeSecurityGroupState结构中) | 规则的优先级 |
| 4.7.21 |
protocol (可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的协议类型 |
| 4.7.21 |
srcIpRange (可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的源方向IP范围 |
| 4.7.21 |
dstIpRange (可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的目的方向IP范围 |
| 4.7.21 |
dstPortRange (可选) | String | body(包含在changeSecurityGroupState结构中) | 规则的目的方向端口范围 |
| 4.7.21 |
systemTags (可选) | List | body | 系统标签 |
| 4.7.21 |
userTags (可选) | List | body | 用户标签 |
| 4.7.21 |
API返回
返回示例
{
"inventory": {
"uuid": "68e4f4b48b51369c8c2ada5cb6c2c3c3",
"securityGroupUuid": "c80ad90499213d3b9989afdbfe498390",
"type": "ingress",
"protocol": "tcp",
"state": "enable",
"srcIpRange": "10.10.10.1-10.10.10.10",
"dstPortRange": "2001-2023",
"action": "RETURN",
"createDate": "Sep 15, 2023 9:57:59 AM",
"lastOpDate": "Sep 15, 2023 9:57:59 AM"
}
}| 名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
| success | boolean | 4.7.21 | |
| error | ErrorCode | 错误码,若不为null,则表示操作失败, 操作成功时该字段为null。 详情参考error | 4.7.21 |
| inventory | SecurityGroupInventory | 详情参考inventory | 4.7.21 |
error
| 名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
| code | String | 错误码号,错误的全局唯一标识,例如SYS.1000, HOST.1001 | 4.7.21 |
| description | String | 错误的概要描述 | 4.7.21 |
| details | String | 错误的详细信息 | 4.7.21 |
| elaboration | String | 保留字段,默认为null | 4.7.21 |
| opaque | LinkedHashMap | 保留字段,默认为null | 4.7.21 |
| cause | ErrorCode | 根错误,引发当前错误的源错误,若无原错误,该字段为null | 4.7.21 |
inventory
名字 | 类型 | 描述 | 起始版本 |
|---|---|---|---|
uuid | String | 资源的UUID,唯一标示该资源 | 4.7.21 |
securityGroupUuid | String | 安全组UUID | 4.7.21 |
type | String | 流量类型 | 4.7.21 |
ipVersion | Integer | ip协议号 | 3.1.0 |
protocol | String | 流量协议类型 | 4.7.21 |
state | String | 规则的可用状态 | 4.7.21 |
priority | Integer | 规则优先级 | 4.7.21 |
description | String | 规则描述 | 4.7.21 |
srcIpRange | String | 源IP范围 | 4.7.21 |
dstIpRange | String | 目的IP范围 | 4.7.21 |
srcPortRange | String | 源端口范围,当前版本未实现 | 4.7.21 |
dstPortRange | String | 目的端口范围 | 4.7.21 |
action | String | 规则的默认动作 | 4.7.21 |
remoteSecurityGroupUuid | String |
| 4.7.21 |
allowedCidr | String | 允许的CIDR,根据流量类型的不同, 允许的CIDR有不同的含义- 如果流量类型是Ingress,允许的CIDR是允许访问虚拟机网卡的源CIDR
| 4.7.21 |
startPort | Integer |
| 4.7.21 |
endPort | Integer |
| 4.7.21 |
createDate | Timestamp | 创建时间 | 4.7.21 |
lastOpDate | Timestamp | 最后一次修改时间 | 4.7.21 |
SDK示例
Java SDK
ChangeSecurityGroupRuleAction action = new ChangeSecurityGroupRuleAction();
action.uuid = "33869c6c323d30599da314fe1e46b01c";
action.description = "test";
action.remoteSecurityGroupUuid = "bd2dcc93fbd73999bf920aeaab3c9e4e";
action.action = "DROP";
action.state = "Enabled";
action.priority = 1;
action.protocol = "TCP";
action.srcIpRange = "1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10";
action.dstPortRange = "1001,2000-2023,6001";
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
ChangeSecurityGroupRuleAction.Result res = action.call();
Python SDK
ChangeSecurityGroupRuleAction action = ChangeSecurityGroupRuleAction()
action.uuid = "33869c6c323d30599da314fe1e46b01c"
action.description = "test"
action.remoteSecurityGroupUuid = "bd2dcc93fbd73999bf920aeaab3c9e4e"
action.action = "DROP"
action.state = "Enabled"
action.priority = 1
action.protocol = "TCP"
action.srcIpRange = "1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10"
action.dstPortRange = "1001,2000-2023,6001"
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
ChangeSecurityGroupRuleAction.Result res = action.call()