com.pulumi.aws.wafregional.WebAcl Maven / Gradle / Ivy
Go to download
Show more of this group Show more artifacts with this name
Show all versions of aws Show documentation
Show all versions of aws Show documentation
A Pulumi package for creating and managing Amazon Web Services (AWS) cloud resources.
// *** WARNING: this file was generated by pulumi-java-gen. ***
// *** Do not edit by hand unless you're certain you know what you are doing! ***
package com.pulumi.aws.wafregional;
import com.pulumi.aws.Utilities;
import com.pulumi.aws.wafregional.WebAclArgs;
import com.pulumi.aws.wafregional.inputs.WebAclState;
import com.pulumi.aws.wafregional.outputs.WebAclDefaultAction;
import com.pulumi.aws.wafregional.outputs.WebAclLoggingConfiguration;
import com.pulumi.aws.wafregional.outputs.WebAclRule;
import com.pulumi.core.Output;
import com.pulumi.core.annotations.Export;
import com.pulumi.core.annotations.ResourceType;
import com.pulumi.core.internal.Codegen;
import java.lang.String;
import java.util.List;
import java.util.Map;
import java.util.Optional;
import javax.annotation.Nullable;
/**
* Provides a WAF Regional Web ACL Resource for use with Application Load Balancer.
*
* ## Example Usage
*
* ### Regular Rule
*
* <!--Start PulumiCodeChooser -->
*
* {@code
* package generated_program;
*
* import com.pulumi.Context;
* import com.pulumi.Pulumi;
* import com.pulumi.core.Output;
* import com.pulumi.aws.wafregional.IpSet;
* import com.pulumi.aws.wafregional.IpSetArgs;
* import com.pulumi.aws.wafregional.inputs.IpSetIpSetDescriptorArgs;
* import com.pulumi.aws.wafregional.Rule;
* import com.pulumi.aws.wafregional.RuleArgs;
* import com.pulumi.aws.wafregional.inputs.RulePredicateArgs;
* import com.pulumi.aws.wafregional.WebAcl;
* import com.pulumi.aws.wafregional.WebAclArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclDefaultActionArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclRuleArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclRuleActionArgs;
* import java.util.List;
* import java.util.ArrayList;
* import java.util.Map;
* import java.io.File;
* import java.nio.file.Files;
* import java.nio.file.Paths;
*
* public class App {
* public static void main(String[] args) {
* Pulumi.run(App::stack);
* }
*
* public static void stack(Context ctx) {
* var ipset = new IpSet("ipset", IpSetArgs.builder()
* .name("tfIPSet")
* .ipSetDescriptors(IpSetIpSetDescriptorArgs.builder()
* .type("IPV4")
* .value("192.0.7.0/24")
* .build())
* .build());
*
* var wafrule = new Rule("wafrule", RuleArgs.builder()
* .name("tfWAFRule")
* .metricName("tfWAFRule")
* .predicates(RulePredicateArgs.builder()
* .dataId(ipset.id())
* .negated(false)
* .type("IPMatch")
* .build())
* .build());
*
* var wafacl = new WebAcl("wafacl", WebAclArgs.builder()
* .name("tfWebACL")
* .metricName("tfWebACL")
* .defaultAction(WebAclDefaultActionArgs.builder()
* .type("ALLOW")
* .build())
* .rules(WebAclRuleArgs.builder()
* .action(WebAclRuleActionArgs.builder()
* .type("BLOCK")
* .build())
* .priority(1)
* .ruleId(wafrule.id())
* .type("REGULAR")
* .build())
* .build());
*
* }
* }
* }
*
* <!--End PulumiCodeChooser -->
*
* ### Group Rule
*
* <!--Start PulumiCodeChooser -->
*
* {@code
* package generated_program;
*
* import com.pulumi.Context;
* import com.pulumi.Pulumi;
* import com.pulumi.core.Output;
* import com.pulumi.aws.wafregional.WebAcl;
* import com.pulumi.aws.wafregional.WebAclArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclDefaultActionArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclRuleArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclRuleOverrideActionArgs;
* import java.util.List;
* import java.util.ArrayList;
* import java.util.Map;
* import java.io.File;
* import java.nio.file.Files;
* import java.nio.file.Paths;
*
* public class App {
* public static void main(String[] args) {
* Pulumi.run(App::stack);
* }
*
* public static void stack(Context ctx) {
* var example = new WebAcl("example", WebAclArgs.builder()
* .name("example")
* .metricName("example")
* .defaultAction(WebAclDefaultActionArgs.builder()
* .type("ALLOW")
* .build())
* .rules(WebAclRuleArgs.builder()
* .priority(1)
* .ruleId(exampleAwsWafregionalRuleGroup.id())
* .type("GROUP")
* .overrideAction(WebAclRuleOverrideActionArgs.builder()
* .type("NONE")
* .build())
* .build())
* .build());
*
* }
* }
* }
*
* <!--End PulumiCodeChooser -->
*
* ### Logging
*
* > *NOTE:* The Kinesis Firehose Delivery Stream name must begin with `aws-waf-logs-`. See the [AWS WAF Developer Guide](https://docs.aws.amazon.com/waf/latest/developerguide/logging.html) for more information about enabling WAF logging.
*
* <!--Start PulumiCodeChooser -->
*
* {@code
* package generated_program;
*
* import com.pulumi.Context;
* import com.pulumi.Pulumi;
* import com.pulumi.core.Output;
* import com.pulumi.aws.wafregional.WebAcl;
* import com.pulumi.aws.wafregional.WebAclArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclLoggingConfigurationArgs;
* import com.pulumi.aws.wafregional.inputs.WebAclLoggingConfigurationRedactedFieldsArgs;
* import java.util.List;
* import java.util.ArrayList;
* import java.util.Map;
* import java.io.File;
* import java.nio.file.Files;
* import java.nio.file.Paths;
*
* public class App {
* public static void main(String[] args) {
* Pulumi.run(App::stack);
* }
*
* public static void stack(Context ctx) {
* var example = new WebAcl("example", WebAclArgs.builder()
* .loggingConfiguration(WebAclLoggingConfigurationArgs.builder()
* .logDestination(exampleAwsKinesisFirehoseDeliveryStream.arn())
* .redactedFields(WebAclLoggingConfigurationRedactedFieldsArgs.builder()
* .fieldToMatches(
* WebAclLoggingConfigurationRedactedFieldsFieldToMatchArgs.builder()
* .type("URI")
* .build(),
* WebAclLoggingConfigurationRedactedFieldsFieldToMatchArgs.builder()
* .data("referer")
* .type("HEADER")
* .build())
* .build())
* .build())
* .build());
*
* }
* }
* }
*
* <!--End PulumiCodeChooser -->
*
* ## Import
*
* Using `pulumi import`, import WAF Regional Web ACL using the id. For example:
*
* ```sh
* $ pulumi import aws:wafregional/webAcl:WebAcl wafacl a1b2c3d4-d5f6-7777-8888-9999aaaabbbbcccc
* ```
*
*/
@ResourceType(type="aws:wafregional/webAcl:WebAcl")
public class WebAcl extends com.pulumi.resources.CustomResource {
/**
* Amazon Resource Name (ARN) of the WAF Regional WebACL.
*
*/
@Export(name="arn", refs={String.class}, tree="[0]")
private Output arn;
/**
* @return Amazon Resource Name (ARN) of the WAF Regional WebACL.
*
*/
public Output arn() {
return this.arn;
}
/**
* The action that you want AWS WAF Regional to take when a request doesn't match the criteria in any of the rules that are associated with the web ACL.
*
*/
@Export(name="defaultAction", refs={WebAclDefaultAction.class}, tree="[0]")
private Output defaultAction;
/**
* @return The action that you want AWS WAF Regional to take when a request doesn't match the criteria in any of the rules that are associated with the web ACL.
*
*/
public Output defaultAction() {
return this.defaultAction;
}
/**
* Configuration block to enable WAF logging. Detailed below.
*
*/
@Export(name="loggingConfiguration", refs={WebAclLoggingConfiguration.class}, tree="[0]")
private Output* @Nullable */ WebAclLoggingConfiguration> loggingConfiguration;
/**
* @return Configuration block to enable WAF logging. Detailed below.
*
*/
public Output> loggingConfiguration() {
return Codegen.optional(this.loggingConfiguration);
}
/**
* The name or description for the Amazon CloudWatch metric of this web ACL.
*
*/
@Export(name="metricName", refs={String.class}, tree="[0]")
private Output metricName;
/**
* @return The name or description for the Amazon CloudWatch metric of this web ACL.
*
*/
public Output metricName() {
return this.metricName;
}
/**
* The name or description of the web ACL.
*
*/
@Export(name="name", refs={String.class}, tree="[0]")
private Output name;
/**
* @return The name or description of the web ACL.
*
*/
public Output name() {
return this.name;
}
/**
* Set of configuration blocks containing rules for the web ACL. Detailed below.
*
*/
@Export(name="rules", refs={List.class,WebAclRule.class}, tree="[0,1]")
private Output* @Nullable */ List> rules;
/**
* @return Set of configuration blocks containing rules for the web ACL. Detailed below.
*
*/
public Output>> rules() {
return Codegen.optional(this.rules);
}
/**
* Key-value map of resource tags. .If configured with a provider `default_tags` configuration block present, tags with matching keys will overwrite those defined at the provider-level.
*
*/
@Export(name="tags", refs={Map.class,String.class}, tree="[0,1,1]")
private Output* @Nullable */ Map> tags;
/**
* @return Key-value map of resource tags. .If configured with a provider `default_tags` configuration block present, tags with matching keys will overwrite those defined at the provider-level.
*
*/
public Output>> tags() {
return Codegen.optional(this.tags);
}
/**
* A map of tags assigned to the resource, including those inherited from the provider `default_tags` configuration block.
*
* @deprecated
* Please use `tags` instead.
*
*/
@Deprecated /* Please use `tags` instead. */
@Export(name="tagsAll", refs={Map.class,String.class}, tree="[0,1,1]")
private Output
© 2015 - 2025 Weber Informatics LLC | Privacy Policy