修改安全组规则

PUT/zstack/v1/security-groups/rules/{uuid}/actions

Headers

Authorization: OAuth the-session-uuid

Body

{
  "changeSecurityGroupRule": {
    "description": "test",
    "remoteSecurityGroupUuid": "bd2dcc93fbd73999bf920aeaab3c9e4e",
    "action": "DROP",
    "state": "Enabled",
    "priority": 1,
    "protocol": "TCP",
    "srcIpRange": "1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10",
    "dstPortRange": "1001,2000-2023,6001"
  },
  "systemTags": [],
  "userTags": []
}

上述示例中systemTagsuserTags字段可以省略。列出是为了表示body中可以包含这两个字段。

Curl示例

curl -H "Content-Type: application/json;charset=UTF-8" 
-H "Authorization: OAuth b86c9016b4f24953a9edefb53ca0678c" 
-X PUT -d '{"changeSecurityGroupRule":{"description":"test","remoteSecurityGroupUuid":"bd2dcc93fbd73999bf920aeaab3c9e4e","action":"DROP","state":"Enabled","priority":1,"protocol":"TCP","srcIpRange":"1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10","dstPortRange":"1001,2000-2023,6001"}}'
http://localhost:8080/zstack/v1/security-groups/85a1d77188d836eab47b34e7129fb5fb/actions

参数列表

名字

类型

位置

描述

可选值

起始版本

uuid

String

url

安全组规则的UUID,唯一标示该资源

 

4.7.21

description(可选)

String

body(包含在changeSecurityGroupState结构中)

规则的描述

 

4.7.21

remoteSecurityGroupUuid (可选)

String

body(包含在changeSecurityGroupState结构中)

应用组间策略的远端安全组UUID

enabledisable

4.7.21

action (可选)

String

body(包含在changeSecurityGroupState结构中)

规则的默认动作

  • DROP
  • ACCEPT

4.7.21

state (可选)

String

body(包含在changeSecurityGroupState结构中)

规则的状态

  • Enabled
  • Disabled

4.7.21

priority (可选)

Integer

body(包含在changeSecurityGroupState结构中)

规则的优先级

 

4.7.21

protocol (可选)

String

body(包含在changeSecurityGroupState结构中)

规则的协议类型

  • ALL
  • TCP
  • UDP
  • ICMP

4.7.21

srcIpRange (可选)

String

body(包含在changeSecurityGroupState结构中)

规则的源方向IP范围

 

4.7.21

dstIpRange (可选)

String

body(包含在changeSecurityGroupState结构中)

规则的目的方向IP范围

 

4.7.21

dstPortRange (可选)

String

body(包含在changeSecurityGroupState结构中)

规则的目的方向端口范围

 

4.7.21

systemTags (可选)

List

body

系统标签

 

4.7.21

userTags (可选)

List

body

用户标签

 

4.7.21

API返回

返回示例

{
  "inventory": {
    "uuid": "68e4f4b48b51369c8c2ada5cb6c2c3c3",
    "securityGroupUuid": "c80ad90499213d3b9989afdbfe498390",
    "type": "ingress",
    "protocol": "tcp",
    "state": "enable",
    "srcIpRange": "10.10.10.1-10.10.10.10",
    "dstPortRange": "2001-2023",
    "action": "RETURN",
    "createDate": "Sep 15, 2023 9:57:59 AM",
    "lastOpDate": "Sep 15, 2023 9:57:59 AM"
  }
}
名字类型描述起始版本
successboolean 4.7.21
errorErrorCode错误码,若不为null,则表示操作失败, 操作成功时该字段为null。 详情参考error4.7.21
inventorySecurityGroupInventory详情参考inventory4.7.21

error

名字类型描述起始版本
codeString错误码号,错误的全局唯一标识,例如SYS.1000, HOST.10014.7.21
descriptionString错误的概要描述4.7.21
detailsString错误的详细信息4.7.21
elaborationString保留字段,默认为null4.7.21
opaqueLinkedHashMap保留字段,默认为null4.7.21
causeErrorCode根错误,引发当前错误的源错误,若无原错误,该字段为null4.7.21

inventory

名字

类型

描述

起始版本

uuid

String

资源的UUID,唯一标示该资源

4.7.21

securityGroupUuid

String

安全组UUID

4.7.21

type

String

流量类型

4.7.21

ipVersion

Integer

ip协议号

3.1.0

protocol

String

流量协议类型

4.7.21

state

String

规则的可用状态

4.7.21

priority

Integer

规则优先级

4.7.21

description

String

规则描述

4.7.21

srcIpRange

String

源IP范围

4.7.21

dstIpRange

String

目的IP范围

4.7.21

srcPortRange

String

源端口范围,当前版本未实现

4.7.21

dstPortRange

String

目的端口范围

4.7.21

action

String

规则的默认动作

4.7.21

remoteSecurityGroupUuid

String

 

4.7.21

allowedCidr

String

允许的CIDR,根据流量类型的不同, 允许的CIDR有不同的含义- 如果流量类型是Ingress,允许的CIDR是允许访问虚拟机网卡的源CIDR

  • 如果流量类型是Egress,允许的CIDR是允许从虚拟机网卡离开并到达的目的地CIDR

4.7.21

startPort

Integer

  • 如果协议是TCP/UDP,它是端口范围(port range)的起始端口号
  • 如果协议是ICMP,它是ICMP类型(type)

4.7.21

endPort

Integer

  • 如果协议是TCP/UDP, 它是端口范围(port range)的起始端口号
  • 如果协议是ICMP, 它是ICMP类型(type)

4.7.21

createDate

Timestamp

创建时间

4.7.21

lastOpDate

Timestamp

最后一次修改时间

4.7.21

SDK示例

Java SDK

ChangeSecurityGroupRuleAction action = new ChangeSecurityGroupRuleAction();
action.uuid = "33869c6c323d30599da314fe1e46b01c";
action.description = "test";
action.remoteSecurityGroupUuid = "bd2dcc93fbd73999bf920aeaab3c9e4e";
action.action = "DROP";
action.state = "Enabled";
action.priority = 1;
action.protocol = "TCP";
action.srcIpRange = "1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10";
action.dstPortRange = "1001,2000-2023,6001";
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c";
ChangeSecurityGroupRuleAction.Result res = action.call();

Python SDK

ChangeSecurityGroupRuleAction action = ChangeSecurityGroupRuleAction()
action.uuid = "33869c6c323d30599da314fe1e46b01c"
action.description = "test"
action.remoteSecurityGroupUuid = "bd2dcc93fbd73999bf920aeaab3c9e4e"
action.action = "DROP"
action.state = "Enabled"
action.priority = 1
action.protocol = "TCP"
action.srcIpRange = "1.1.1.1,2.2.2.0/24,3.3.3.1-3.3.3.10"
action.dstPortRange = "1001,2000-2023,6001"
action.sessionId = "b86c9016b4f24953a9edefb53ca0678c"
ChangeSecurityGroupRuleAction.Result res = action.call()