mirror of
https://github.com/googleapis/googleapis.git
synced 2026-08-16 13:00:34 +02:00
1348 lines
52 KiB
Protocol Buffer
1348 lines
52 KiB
Protocol Buffer
// Copyright 2025 Google LLC
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
syntax = "proto3";
|
|
|
|
package google.cloud.networksecurity.v1alpha1;
|
|
|
|
import "google/api/annotations.proto";
|
|
import "google/api/client.proto";
|
|
import "google/api/field_behavior.proto";
|
|
import "google/api/field_info.proto";
|
|
import "google/api/resource.proto";
|
|
import "google/cloud/networksecurity/v1alpha1/common.proto";
|
|
import "google/longrunning/operations.proto";
|
|
import "google/protobuf/empty.proto";
|
|
import "google/protobuf/field_mask.proto";
|
|
import "google/protobuf/timestamp.proto";
|
|
|
|
option csharp_namespace = "Google.Cloud.NetworkSecurity.V1Alpha1";
|
|
option go_package = "cloud.google.com/go/networksecurity/apiv1alpha1/networksecuritypb;networksecuritypb";
|
|
option java_multiple_files = true;
|
|
option java_outer_classname = "InterceptProto";
|
|
option java_package = "com.google.cloud.networksecurity.v1alpha1";
|
|
option php_namespace = "Google\\Cloud\\NetworkSecurity\\V1alpha1";
|
|
option ruby_package = "Google::Cloud::NetworkSecurity::V1alpha1";
|
|
|
|
// Service for Third-Party Packet Intercept (TPPI).
|
|
// TPPI is the "in-band" flavor of the Network Security Integrations product.
|
|
service Intercept {
|
|
option (google.api.default_host) = "networksecurity.googleapis.com";
|
|
option (google.api.oauth_scopes) =
|
|
"https://www.googleapis.com/auth/cloud-platform";
|
|
|
|
// Lists endpoint groups in a given project and location.
|
|
// See https://google.aip.dev/132.
|
|
rpc ListInterceptEndpointGroups(ListInterceptEndpointGroupsRequest)
|
|
returns (ListInterceptEndpointGroupsResponse) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{parent=projects/*/locations/*}/interceptEndpointGroups"
|
|
};
|
|
option (google.api.method_signature) = "parent";
|
|
}
|
|
|
|
// Gets a specific endpoint group.
|
|
// See https://google.aip.dev/131.
|
|
rpc GetInterceptEndpointGroup(GetInterceptEndpointGroupRequest)
|
|
returns (InterceptEndpointGroup) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{name=projects/*/locations/*/interceptEndpointGroups/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
}
|
|
|
|
// Creates an endpoint group in a given project and location.
|
|
// See https://google.aip.dev/133.
|
|
rpc CreateInterceptEndpointGroup(CreateInterceptEndpointGroupRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
post: "/v1alpha1/{parent=projects/*/locations/*}/interceptEndpointGroups"
|
|
body: "intercept_endpoint_group"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"parent,intercept_endpoint_group,intercept_endpoint_group_id";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptEndpointGroup"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Updates an endpoint group.
|
|
// See https://google.aip.dev/134.
|
|
rpc UpdateInterceptEndpointGroup(UpdateInterceptEndpointGroupRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
patch: "/v1alpha1/{intercept_endpoint_group.name=projects/*/locations/*/interceptEndpointGroups/*}"
|
|
body: "intercept_endpoint_group"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"intercept_endpoint_group,update_mask";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptEndpointGroup"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Deletes an endpoint group.
|
|
// See https://google.aip.dev/135.
|
|
rpc DeleteInterceptEndpointGroup(DeleteInterceptEndpointGroupRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
delete: "/v1alpha1/{name=projects/*/locations/*/interceptEndpointGroups/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "google.protobuf.Empty"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Lists associations in a given project and location.
|
|
// See https://google.aip.dev/132.
|
|
rpc ListInterceptEndpointGroupAssociations(
|
|
ListInterceptEndpointGroupAssociationsRequest)
|
|
returns (ListInterceptEndpointGroupAssociationsResponse) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{parent=projects/*/locations/*}/interceptEndpointGroupAssociations"
|
|
};
|
|
option (google.api.method_signature) = "parent";
|
|
}
|
|
|
|
// Gets a specific association.
|
|
// See https://google.aip.dev/131.
|
|
rpc GetInterceptEndpointGroupAssociation(
|
|
GetInterceptEndpointGroupAssociationRequest)
|
|
returns (InterceptEndpointGroupAssociation) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{name=projects/*/locations/*/interceptEndpointGroupAssociations/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
}
|
|
|
|
// Creates an association in a given project and location.
|
|
// See https://google.aip.dev/133.
|
|
rpc CreateInterceptEndpointGroupAssociation(
|
|
CreateInterceptEndpointGroupAssociationRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
post: "/v1alpha1/{parent=projects/*/locations/*}/interceptEndpointGroupAssociations"
|
|
body: "intercept_endpoint_group_association"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"parent,intercept_endpoint_group_association,intercept_endpoint_group_association_id";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptEndpointGroupAssociation"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Updates an association.
|
|
// See https://google.aip.dev/134.
|
|
rpc UpdateInterceptEndpointGroupAssociation(
|
|
UpdateInterceptEndpointGroupAssociationRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
patch: "/v1alpha1/{intercept_endpoint_group_association.name=projects/*/locations/*/interceptEndpointGroupAssociations/*}"
|
|
body: "intercept_endpoint_group_association"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"intercept_endpoint_group_association,update_mask";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptEndpointGroupAssociation"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Deletes an association.
|
|
// See https://google.aip.dev/135.
|
|
rpc DeleteInterceptEndpointGroupAssociation(
|
|
DeleteInterceptEndpointGroupAssociationRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
delete: "/v1alpha1/{name=projects/*/locations/*/interceptEndpointGroupAssociations/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "google.protobuf.Empty"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Lists deployment groups in a given project and location.
|
|
// See https://google.aip.dev/132.
|
|
rpc ListInterceptDeploymentGroups(ListInterceptDeploymentGroupsRequest)
|
|
returns (ListInterceptDeploymentGroupsResponse) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{parent=projects/*/locations/*}/interceptDeploymentGroups"
|
|
};
|
|
option (google.api.method_signature) = "parent";
|
|
}
|
|
|
|
// Gets a specific deployment group.
|
|
// See https://google.aip.dev/131.
|
|
rpc GetInterceptDeploymentGroup(GetInterceptDeploymentGroupRequest)
|
|
returns (InterceptDeploymentGroup) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{name=projects/*/locations/*/interceptDeploymentGroups/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
}
|
|
|
|
// Creates a deployment group in a given project and location.
|
|
// See https://google.aip.dev/133.
|
|
rpc CreateInterceptDeploymentGroup(CreateInterceptDeploymentGroupRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
post: "/v1alpha1/{parent=projects/*/locations/*}/interceptDeploymentGroups"
|
|
body: "intercept_deployment_group"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"parent,intercept_deployment_group,intercept_deployment_group_id";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptDeploymentGroup"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Updates a deployment group.
|
|
// See https://google.aip.dev/134.
|
|
rpc UpdateInterceptDeploymentGroup(UpdateInterceptDeploymentGroupRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
patch: "/v1alpha1/{intercept_deployment_group.name=projects/*/locations/*/interceptDeploymentGroups/*}"
|
|
body: "intercept_deployment_group"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"intercept_deployment_group,update_mask";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptDeploymentGroup"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Deletes a deployment group.
|
|
// See https://google.aip.dev/135.
|
|
rpc DeleteInterceptDeploymentGroup(DeleteInterceptDeploymentGroupRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
delete: "/v1alpha1/{name=projects/*/locations/*/interceptDeploymentGroups/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "google.protobuf.Empty"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Lists deployments in a given project and location.
|
|
// See https://google.aip.dev/132.
|
|
rpc ListInterceptDeployments(ListInterceptDeploymentsRequest)
|
|
returns (ListInterceptDeploymentsResponse) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{parent=projects/*/locations/*}/interceptDeployments"
|
|
};
|
|
option (google.api.method_signature) = "parent";
|
|
}
|
|
|
|
// Gets a specific deployment.
|
|
// See https://google.aip.dev/131.
|
|
rpc GetInterceptDeployment(GetInterceptDeploymentRequest)
|
|
returns (InterceptDeployment) {
|
|
option (google.api.http) = {
|
|
get: "/v1alpha1/{name=projects/*/locations/*/interceptDeployments/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
}
|
|
|
|
// Creates a deployment in a given project and location.
|
|
// See https://google.aip.dev/133.
|
|
rpc CreateInterceptDeployment(CreateInterceptDeploymentRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
post: "/v1alpha1/{parent=projects/*/locations/*}/interceptDeployments"
|
|
body: "intercept_deployment"
|
|
};
|
|
option (google.api.method_signature) =
|
|
"parent,intercept_deployment,intercept_deployment_id";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptDeployment"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Updates a deployment.
|
|
// See https://google.aip.dev/134.
|
|
rpc UpdateInterceptDeployment(UpdateInterceptDeploymentRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
patch: "/v1alpha1/{intercept_deployment.name=projects/*/locations/*/interceptDeployments/*}"
|
|
body: "intercept_deployment"
|
|
};
|
|
option (google.api.method_signature) = "intercept_deployment,update_mask";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "InterceptDeployment"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
|
|
// Deletes a deployment.
|
|
// See https://google.aip.dev/135.
|
|
rpc DeleteInterceptDeployment(DeleteInterceptDeploymentRequest)
|
|
returns (google.longrunning.Operation) {
|
|
option (google.api.http) = {
|
|
delete: "/v1alpha1/{name=projects/*/locations/*/interceptDeployments/*}"
|
|
};
|
|
option (google.api.method_signature) = "name";
|
|
option (google.longrunning.operation_info) = {
|
|
response_type: "google.protobuf.Empty"
|
|
metadata_type: "google.cloud.networksecurity.v1alpha1.OperationMetadata"
|
|
};
|
|
}
|
|
}
|
|
|
|
// An endpoint group is a consumer frontend for a deployment group (backend).
|
|
// In order to configure intercept for a network, consumers must create:
|
|
// - An association between their network and the endpoint group.
|
|
// - A security profile that points to the endpoint group.
|
|
// - A firewall rule that references the security profile (group).
|
|
message InterceptEndpointGroup {
|
|
option (google.api.resource) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
pattern: "projects/{project}/locations/{location}/interceptEndpointGroups/{intercept_endpoint_group}"
|
|
plural: "interceptEndpointGroups"
|
|
singular: "interceptEndpointGroup"
|
|
};
|
|
|
|
// The endpoint group's view of a connected deployment group.
|
|
message ConnectedDeploymentGroup {
|
|
// Output only. The connected deployment group's resource name, for example:
|
|
// `projects/123456789/locations/global/interceptDeploymentGroups/my-dg`.
|
|
// See https://google.aip.dev/124.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = OUTPUT_ONLY,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
|
|
// Output only. The list of locations where the deployment group is present.
|
|
repeated InterceptLocation locations = 2
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|
|
|
|
// The endpoint group's view of a connected association.
|
|
message AssociationDetails {
|
|
// Output only. The connected association's resource name, for example:
|
|
// `projects/123456789/locations/global/interceptEndpointGroupAssociations/my-ega`.
|
|
// See https://google.aip.dev/124.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = OUTPUT_ONLY,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroupAssociation"
|
|
}
|
|
];
|
|
|
|
// Output only. The associated network, for example:
|
|
// projects/123456789/global/networks/my-network.
|
|
// See https://google.aip.dev/124.
|
|
string network = 2 [
|
|
(google.api.field_behavior) = OUTPUT_ONLY,
|
|
(google.api.resource_reference) = {
|
|
type: "compute.googleapis.com/Network"
|
|
}
|
|
];
|
|
|
|
// Output only. Most recent known state of the association.
|
|
InterceptEndpointGroupAssociation.State state = 3
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|
|
|
|
// Endpoint group state.
|
|
enum State {
|
|
// State not set (this is not a valid state).
|
|
STATE_UNSPECIFIED = 0;
|
|
|
|
// The endpoint group is ready and in sync with the target deployment group.
|
|
ACTIVE = 1;
|
|
|
|
// The deployment group backing this endpoint group has been force-deleted.
|
|
// This endpoint group cannot be used and interception is effectively
|
|
// disabled.
|
|
CLOSED = 2;
|
|
|
|
// The endpoint group is being created.
|
|
CREATING = 3;
|
|
|
|
// The endpoint group is being deleted.
|
|
DELETING = 4;
|
|
|
|
// The endpoint group is out of sync with the backing deployment group.
|
|
// In most cases, this is a result of a transient issue within the system
|
|
// (e.g. an inaccessible location) and the system is expected to recover
|
|
// automatically. See the associations field for details per network and
|
|
// location.
|
|
OUT_OF_SYNC = 5;
|
|
|
|
// An attempt to delete the endpoint group has failed. This is a terminal
|
|
// state and the endpoint group is not expected to recover.
|
|
// The only permitted operation is to retry deleting the endpoint group.
|
|
DELETE_FAILED = 6;
|
|
}
|
|
|
|
// Immutable. Identifier. The resource name of this endpoint group, for
|
|
// example:
|
|
// `projects/123456789/locations/global/interceptEndpointGroups/my-eg`.
|
|
// See https://google.aip.dev/122 for more details.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = IDENTIFIER,
|
|
(google.api.field_behavior) = IMMUTABLE
|
|
];
|
|
|
|
// Output only. The timestamp when the resource was created.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp create_time = 2
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The timestamp when the resource was most recently updated.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp update_time = 3
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. Labels are key/value pairs that help to organize and filter
|
|
// resources.
|
|
map<string, string> labels = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. Immutable. The deployment group that this endpoint group is
|
|
// connected to, for example:
|
|
// `projects/123456789/locations/global/interceptDeploymentGroups/my-dg`.
|
|
// See https://google.aip.dev/124.
|
|
string intercept_deployment_group = 5 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.field_behavior) = IMMUTABLE,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
|
|
// Output only. Details about the connected deployment group to this endpoint
|
|
// group.
|
|
ConnectedDeploymentGroup connected_deployment_group = 11
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the endpoint group.
|
|
// See https://google.aip.dev/216.
|
|
State state = 7 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the resource does not match the user's
|
|
// intended state, and the system is working to reconcile them. This is part
|
|
// of the normal operation (e.g. adding a new association to the group). See
|
|
// https://google.aip.dev/128.
|
|
bool reconciling = 8 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. List of associations to this endpoint group.
|
|
repeated AssociationDetails associations = 9
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. User-provided description of the endpoint group.
|
|
// Used as additional context for the endpoint group.
|
|
string description = 10 [(google.api.field_behavior) = OPTIONAL];
|
|
}
|
|
|
|
// Request message for ListInterceptEndpointGroups.
|
|
message ListInterceptEndpointGroupsRequest {
|
|
// Required. The parent, which owns this collection of endpoint groups.
|
|
// Example: `projects/123456789/locations/global`.
|
|
// See https://google.aip.dev/132 for more details.
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
}
|
|
];
|
|
|
|
// Optional. Requested page size. Server may return fewer items than
|
|
// requested. If unspecified, server will pick an appropriate default. See
|
|
// https://google.aip.dev/158 for more details.
|
|
int32 page_size = 2 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. A page token, received from a previous
|
|
// `ListInterceptEndpointGroups` call. Provide this to retrieve the subsequent
|
|
// page. When paginating, all other parameters provided to
|
|
// `ListInterceptEndpointGroups` must match the call that provided the page
|
|
// token.
|
|
// See https://google.aip.dev/158 for more details.
|
|
string page_token = 3 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Filter expression.
|
|
// See https://google.aip.dev/160#filtering for more details.
|
|
string filter = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Sort expression.
|
|
// See https://google.aip.dev/132#ordering for more details.
|
|
string order_by = 5 [(google.api.field_behavior) = OPTIONAL];
|
|
}
|
|
|
|
// Response message for ListInterceptEndpointGroups.
|
|
message ListInterceptEndpointGroupsResponse {
|
|
// The endpoint groups from the specified parent.
|
|
repeated InterceptEndpointGroup intercept_endpoint_groups = 1;
|
|
|
|
// A token that can be sent as `page_token` to retrieve the next page.
|
|
// If this field is omitted, there are no subsequent pages.
|
|
// See https://google.aip.dev/158 for more details.
|
|
string next_page_token = 2;
|
|
}
|
|
|
|
// Request message for GetInterceptEndpointGroup.
|
|
message GetInterceptEndpointGroupRequest {
|
|
// Required. The name of the endpoint group to retrieve.
|
|
// Format:
|
|
// projects/{project}/locations/{location}/interceptEndpointGroups/{intercept_endpoint_group}
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
}
|
|
];
|
|
}
|
|
|
|
// Request message for CreateInterceptEndpointGroup.
|
|
message CreateInterceptEndpointGroupRequest {
|
|
// Required. The parent resource where this endpoint group will be created.
|
|
// Format: projects/{project}/locations/{location}
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
}
|
|
];
|
|
|
|
// Required. The ID to use for the endpoint group, which will become the final
|
|
// component of the endpoint group's resource name.
|
|
string intercept_endpoint_group_id = 2
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Required. The endpoint group to create.
|
|
InterceptEndpointGroup intercept_endpoint_group = 3
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 4 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for UpdateInterceptEndpointGroup.
|
|
message UpdateInterceptEndpointGroupRequest {
|
|
// Optional. The list of fields to update.
|
|
// Fields are specified relative to the endpoint group
|
|
// (e.g. `description`; *not* `intercept_endpoint_group.description`).
|
|
// See https://google.aip.dev/161 for more details.
|
|
google.protobuf.FieldMask update_mask = 1
|
|
[(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. The endpoint group to update.
|
|
InterceptEndpointGroup intercept_endpoint_group = 2
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 3 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for DeleteInterceptEndpointGroup.
|
|
message DeleteInterceptEndpointGroupRequest {
|
|
// Required. The endpoint group to delete.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
}
|
|
];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 2 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// An endpoint group association represents a link between a network and an
|
|
// endpoint group in the organization.
|
|
//
|
|
// Creating an association creates the networking infrastructure linking the
|
|
// network to the endpoint group, but does not enable intercept by itself.
|
|
// To enable intercept, the user must also create a network firewall policy
|
|
// containing intercept rules and associate it with the network.
|
|
message InterceptEndpointGroupAssociation {
|
|
option (google.api.resource) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroupAssociation"
|
|
pattern: "projects/{project}/locations/{location}/interceptEndpointGroupAssociations/{intercept_endpoint_group_association}"
|
|
plural: "interceptEndpointGroupAssociations"
|
|
singular: "interceptEndpointGroupAssociation"
|
|
};
|
|
|
|
// Contains details about the state of an association in a specific cloud
|
|
// location.
|
|
message LocationDetails {
|
|
// The state of association.
|
|
enum State {
|
|
// Not set.
|
|
STATE_UNSPECIFIED = 0;
|
|
|
|
// The association is ready and in sync with the linked endpoint group.
|
|
ACTIVE = 1;
|
|
|
|
// The association is out of sync with the linked endpoint group.
|
|
// In most cases, this is a result of a transient issue within the system
|
|
// (e.g. an inaccessible location) and the system is expected to recover
|
|
// automatically.
|
|
OUT_OF_SYNC = 2;
|
|
}
|
|
|
|
// Output only. The cloud location, e.g. "us-central1-a" or "asia-south1".
|
|
string location = 1 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the association in this location.
|
|
State state = 2 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|
|
|
|
// The state of the association.
|
|
enum State {
|
|
// Not set.
|
|
STATE_UNSPECIFIED = 0;
|
|
|
|
// The association is ready and in sync with the linked endpoint group.
|
|
ACTIVE = 1;
|
|
|
|
// The association is being created.
|
|
CREATING = 2;
|
|
|
|
// The association is being deleted.
|
|
DELETING = 3;
|
|
|
|
// The association is disabled due to a breaking change in another resource.
|
|
CLOSED = 4;
|
|
|
|
// The association is out of sync with the linked endpoint group.
|
|
// In most cases, this is a result of a transient issue within the system
|
|
// (e.g. an inaccessible location) and the system is expected to recover
|
|
// automatically. Check the `locations_details` field for more details.
|
|
OUT_OF_SYNC = 5;
|
|
|
|
// An attempt to delete the association has failed. This is a terminal state
|
|
// and the association is not expected to be usable as some of its resources
|
|
// have been deleted.
|
|
// The only permitted operation is to retry deleting the association.
|
|
DELETE_FAILED = 6;
|
|
}
|
|
|
|
// Immutable. Identifier. The resource name of this endpoint group
|
|
// association, for example:
|
|
// `projects/123456789/locations/global/interceptEndpointGroupAssociations/my-eg-association`.
|
|
// See https://google.aip.dev/122 for more details.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = IDENTIFIER,
|
|
(google.api.field_behavior) = IMMUTABLE
|
|
];
|
|
|
|
// Output only. The timestamp when the resource was created.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp create_time = 2
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The timestamp when the resource was most recently updated.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp update_time = 3
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. Labels are key/value pairs that help to organize and filter
|
|
// resources.
|
|
map<string, string> labels = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. Immutable. The endpoint group that this association is connected
|
|
// to, for example:
|
|
// `projects/123456789/locations/global/interceptEndpointGroups/my-eg`.
|
|
// See https://google.aip.dev/124.
|
|
string intercept_endpoint_group = 5 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.field_behavior) = IMMUTABLE,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
}
|
|
];
|
|
|
|
// Required. Immutable. The VPC network that is associated. for example:
|
|
// `projects/123456789/global/networks/my-network`.
|
|
// See https://google.aip.dev/124.
|
|
string network = 6 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.field_behavior) = IMMUTABLE,
|
|
(google.api.resource_reference) = { type: "compute.googleapis.com/Network" }
|
|
];
|
|
|
|
// Output only. The list of locations where the association is present. This
|
|
// information is retrieved from the linked endpoint group, and not configured
|
|
// as part of the association itself.
|
|
repeated LocationDetails locations_details = 7
|
|
[deprecated = true, (google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. Current state of the endpoint group association.
|
|
State state = 8 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the resource does not match the user's
|
|
// intended state, and the system is working to reconcile them. This part of
|
|
// the normal operation (e.g. adding a new location to the target deployment
|
|
// group). See https://google.aip.dev/128.
|
|
bool reconciling = 9 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The list of locations where the association is configured.
|
|
// This information is retrieved from the linked endpoint group.
|
|
repeated InterceptLocation locations = 10
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|
|
|
|
// Request message for ListInterceptEndpointGroupAssociations.
|
|
message ListInterceptEndpointGroupAssociationsRequest {
|
|
// Required. The parent, which owns this collection of associations.
|
|
// Example: `projects/123456789/locations/global`.
|
|
// See https://google.aip.dev/132 for more details.
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptEndpointGroupAssociation"
|
|
}
|
|
];
|
|
|
|
// Optional. Requested page size. Server may return fewer items than
|
|
// requested. If unspecified, server will pick an appropriate default. See
|
|
// https://google.aip.dev/158 for more details.
|
|
int32 page_size = 2 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. A page token, received from a previous
|
|
// `ListInterceptEndpointGroups` call. Provide this to retrieve the subsequent
|
|
// page. When paginating, all other parameters provided to
|
|
// `ListInterceptEndpointGroups` must match the call that provided the page
|
|
// token. See https://google.aip.dev/158 for more details.
|
|
string page_token = 3 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Filter expression.
|
|
// See https://google.aip.dev/160#filtering for more details.
|
|
string filter = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Sort expression.
|
|
// See https://google.aip.dev/132#ordering for more details.
|
|
string order_by = 5 [(google.api.field_behavior) = OPTIONAL];
|
|
}
|
|
|
|
// Response message for ListInterceptEndpointGroupAssociations.
|
|
message ListInterceptEndpointGroupAssociationsResponse {
|
|
// The associations from the specified parent.
|
|
repeated InterceptEndpointGroupAssociation
|
|
intercept_endpoint_group_associations = 1;
|
|
|
|
// A token that can be sent as `page_token` to retrieve the next page.
|
|
// If this field is omitted, there are no subsequent pages.
|
|
// See https://google.aip.dev/158 for more details.
|
|
string next_page_token = 2;
|
|
}
|
|
|
|
// Request message for GetInterceptEndpointGroupAssociation.
|
|
message GetInterceptEndpointGroupAssociationRequest {
|
|
// Required. The name of the association to retrieve.
|
|
// Format:
|
|
// projects/{project}/locations/{location}/interceptEndpointGroupAssociations/{intercept_endpoint_group_association}
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroupAssociation"
|
|
}
|
|
];
|
|
}
|
|
|
|
// Request message for CreateInterceptEndpointGroupAssociation.
|
|
message CreateInterceptEndpointGroupAssociationRequest {
|
|
// Required. The parent resource where this association will be created.
|
|
// Format: projects/{project}/locations/{location}
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptEndpointGroupAssociation"
|
|
}
|
|
];
|
|
|
|
// Optional. The ID to use for the new association, which will become the
|
|
// final component of the endpoint group's resource name. If not provided, the
|
|
// server will generate a unique ID.
|
|
string intercept_endpoint_group_association_id = 2
|
|
[(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. The association to create.
|
|
InterceptEndpointGroupAssociation intercept_endpoint_group_association = 3
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 4 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for UpdateInterceptEndpointGroupAssociation.
|
|
message UpdateInterceptEndpointGroupAssociationRequest {
|
|
// Optional. The list of fields to update.
|
|
// Fields are specified relative to the association
|
|
// (e.g. `description`; *not*
|
|
// `intercept_endpoint_group_association.description`). See
|
|
// https://google.aip.dev/161 for more details.
|
|
google.protobuf.FieldMask update_mask = 1
|
|
[(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. The association to update.
|
|
InterceptEndpointGroupAssociation intercept_endpoint_group_association = 2
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 3 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for DeleteInterceptEndpointGroupAssociation.
|
|
message DeleteInterceptEndpointGroupAssociationRequest {
|
|
// Required. The association to delete.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroupAssociation"
|
|
}
|
|
];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 2 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// A deployment group aggregates many zonal intercept backends (deployments)
|
|
// into a single global intercept service. Consumers can connect this service
|
|
// using an endpoint group.
|
|
message InterceptDeploymentGroup {
|
|
option (google.api.resource) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
pattern: "projects/{project}/locations/{location}/interceptDeploymentGroups/{intercept_deployment_group}"
|
|
plural: "interceptDeploymentGroups"
|
|
singular: "interceptDeploymentGroup"
|
|
};
|
|
|
|
// An endpoint group connected to this deployment group.
|
|
message ConnectedEndpointGroup {
|
|
// Output only. The connected endpoint group's resource name, for example:
|
|
// `projects/123456789/locations/global/interceptEndpointGroups/my-eg`.
|
|
// See https://google.aip.dev/124.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = OUTPUT_ONLY,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptEndpointGroup"
|
|
}
|
|
];
|
|
}
|
|
|
|
// A deployment belonging to this deployment group.
|
|
message Deployment {
|
|
// Output only. The name of the Intercept Deployment, in the format:
|
|
// `projects/{project}/locations/{location}/interceptDeployments/{intercept_deployment}`.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = OUTPUT_ONLY,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeployment"
|
|
}
|
|
];
|
|
|
|
// Output only. Most recent known state of the deployment.
|
|
InterceptDeployment.State state = 2
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|
|
|
|
// The current state of the deployment group.
|
|
enum State {
|
|
// State not set (this is not a valid state).
|
|
STATE_UNSPECIFIED = 0;
|
|
|
|
// The deployment group is ready.
|
|
ACTIVE = 1;
|
|
|
|
// The deployment group is being created.
|
|
CREATING = 2;
|
|
|
|
// The deployment group is being deleted.
|
|
DELETING = 3;
|
|
}
|
|
|
|
// Immutable. Identifier. The resource name of this deployment group, for
|
|
// example:
|
|
// `projects/123456789/locations/global/interceptDeploymentGroups/my-dg`.
|
|
// See https://google.aip.dev/122 for more details.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = IDENTIFIER,
|
|
(google.api.field_behavior) = IMMUTABLE
|
|
];
|
|
|
|
// Output only. The timestamp when the resource was created.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp create_time = 2
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The timestamp when the resource was most recently updated.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp update_time = 3
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. Labels are key/value pairs that help to organize and filter
|
|
// resources.
|
|
map<string, string> labels = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. Immutable. The network that will be used for all child
|
|
// deployments, for example: `projects/{project}/global/networks/{network}`.
|
|
// See https://google.aip.dev/124.
|
|
string network = 5 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.field_behavior) = IMMUTABLE,
|
|
(google.api.resource_reference) = { type: "compute.googleapis.com/Network" }
|
|
];
|
|
|
|
// Output only. The list of endpoint groups that are connected to this
|
|
// resource.
|
|
repeated ConnectedEndpointGroup connected_endpoint_groups = 6
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The list of Intercept Deployments that belong to this group.
|
|
repeated Deployment nested_deployments = 10
|
|
[deprecated = true, (google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the deployment group.
|
|
// See https://google.aip.dev/216.
|
|
State state = 7 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the resource does not match the user's
|
|
// intended state, and the system is working to reconcile them. This is part
|
|
// of the normal operation (e.g. adding a new deployment to the group) See
|
|
// https://google.aip.dev/128.
|
|
bool reconciling = 8 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. User-provided description of the deployment group.
|
|
// Used as additional context for the deployment group.
|
|
string description = 9 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Output only. The list of locations where the deployment group is present.
|
|
repeated InterceptLocation locations = 11
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|
|
|
|
// Request message for ListInterceptDeploymentGroups.
|
|
message ListInterceptDeploymentGroupsRequest {
|
|
// Required. The parent, which owns this collection of deployment groups.
|
|
// Example: `projects/123456789/locations/global`.
|
|
// See https://google.aip.dev/132 for more details.
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
|
|
// Optional. Requested page size. Server may return fewer items than
|
|
// requested. If unspecified, server will pick an appropriate default. See
|
|
// https://google.aip.dev/158 for more details.
|
|
int32 page_size = 2 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. A page token, received from a previous
|
|
// `ListInterceptDeploymentGroups` call. Provide this to retrieve the
|
|
// subsequent page. When paginating, all other parameters provided to
|
|
// `ListInterceptDeploymentGroups` must match the call that provided the page
|
|
// token. See https://google.aip.dev/158 for more details.
|
|
string page_token = 3 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Filter expression.
|
|
// See https://google.aip.dev/160#filtering for more details.
|
|
string filter = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Sort expression.
|
|
// See https://google.aip.dev/132#ordering for more details.
|
|
string order_by = 5 [(google.api.field_behavior) = OPTIONAL];
|
|
}
|
|
|
|
// Response message for ListInterceptDeploymentGroups.
|
|
message ListInterceptDeploymentGroupsResponse {
|
|
// The deployment groups from the specified parent.
|
|
repeated InterceptDeploymentGroup intercept_deployment_groups = 1;
|
|
|
|
// A token that can be sent as `page_token` to retrieve the next page.
|
|
// If this field is omitted, there are no subsequent pages.
|
|
// See https://google.aip.dev/158 for more details.
|
|
string next_page_token = 2;
|
|
}
|
|
|
|
// Request message for GetInterceptDeploymentGroup.
|
|
message GetInterceptDeploymentGroupRequest {
|
|
// Required. The name of the deployment group to retrieve.
|
|
// Format:
|
|
// projects/{project}/locations/{location}/interceptDeploymentGroups/{intercept_deployment_group}
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
}
|
|
|
|
// Request message for CreateInterceptDeploymentGroup.
|
|
message CreateInterceptDeploymentGroupRequest {
|
|
// Required. The parent resource where this deployment group will be created.
|
|
// Format: projects/{project}/locations/{location}
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
|
|
// Required. The ID to use for the new deployment group, which will become the
|
|
// final component of the deployment group's resource name.
|
|
string intercept_deployment_group_id = 2
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Required. The deployment group to create.
|
|
InterceptDeploymentGroup intercept_deployment_group = 3
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 4 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for UpdateInterceptDeploymentGroup.
|
|
message UpdateInterceptDeploymentGroupRequest {
|
|
// Optional. The list of fields to update.
|
|
// Fields are specified relative to the deployment group
|
|
// (e.g. `description`; *not*
|
|
// `intercept_deployment_group.description`). See
|
|
// https://google.aip.dev/161 for more details.
|
|
google.protobuf.FieldMask update_mask = 1
|
|
[(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. The deployment group to update.
|
|
InterceptDeploymentGroup intercept_deployment_group = 2
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 3 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for DeleteInterceptDeploymentGroup.
|
|
message DeleteInterceptDeploymentGroupRequest {
|
|
// Required. The deployment group to delete.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 2 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// A deployment represents a zonal intercept backend ready to accept
|
|
// GENEVE-encapsulated traffic, e.g. a zonal instance group fronted by an
|
|
// internal passthrough load balancer. Deployments are always part of a
|
|
// global deployment group which represents a global intercept service.
|
|
message InterceptDeployment {
|
|
option (google.api.resource) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeployment"
|
|
pattern: "projects/{project}/locations/{location}/interceptDeployments/{intercept_deployment}"
|
|
plural: "interceptDeployments"
|
|
singular: "interceptDeployment"
|
|
};
|
|
|
|
// The current state of the deployment.
|
|
enum State {
|
|
// State not set (this is not a valid state).
|
|
STATE_UNSPECIFIED = 0;
|
|
|
|
// The deployment is ready and in sync with the parent group.
|
|
ACTIVE = 1;
|
|
|
|
// The deployment is being created.
|
|
CREATING = 2;
|
|
|
|
// The deployment is being deleted.
|
|
DELETING = 3;
|
|
|
|
// The deployment is out of sync with the parent group.
|
|
// In most cases, this is a result of a transient issue within the system
|
|
// (e.g. a delayed data-path config) and the system is expected to recover
|
|
// automatically. See the parent deployment group's state for more details.
|
|
OUT_OF_SYNC = 4;
|
|
|
|
// An attempt to delete the deployment has failed. This is a terminal state
|
|
// and the deployment is not expected to recover. The only permitted
|
|
// operation is to retry deleting the deployment.
|
|
DELETE_FAILED = 5;
|
|
}
|
|
|
|
// Immutable. Identifier. The resource name of this deployment, for example:
|
|
// `projects/123456789/locations/us-central1-a/interceptDeployments/my-dep`.
|
|
// See https://google.aip.dev/122 for more details.
|
|
string name = 1 [
|
|
(google.api.field_behavior) = IDENTIFIER,
|
|
(google.api.field_behavior) = IMMUTABLE
|
|
];
|
|
|
|
// Output only. The timestamp when the resource was created.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp create_time = 2
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The timestamp when the resource was most recently updated.
|
|
// See https://google.aip.dev/148#timestamps.
|
|
google.protobuf.Timestamp update_time = 3
|
|
[(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. Labels are key/value pairs that help to organize and filter
|
|
// resources.
|
|
map<string, string> labels = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. Immutable. The regional forwarding rule that fronts the
|
|
// interceptors, for example:
|
|
// `projects/123456789/regions/us-central1/forwardingRules/my-rule`.
|
|
// See https://google.aip.dev/124.
|
|
string forwarding_rule = 5 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.field_behavior) = IMMUTABLE,
|
|
(google.api.resource_reference) = {
|
|
type: "compute.googleapis.com/ForwardingRule"
|
|
}
|
|
];
|
|
|
|
// Required. Immutable. The deployment group that this deployment is a part
|
|
// of, for example:
|
|
// `projects/123456789/locations/global/interceptDeploymentGroups/my-dg`.
|
|
// See https://google.aip.dev/124.
|
|
string intercept_deployment_group = 6 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.field_behavior) = IMMUTABLE,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeploymentGroup"
|
|
}
|
|
];
|
|
|
|
// Output only. The current state of the deployment.
|
|
// See https://google.aip.dev/216.
|
|
State state = 7 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the resource does not match the user's
|
|
// intended state, and the system is working to reconcile them. This part of
|
|
// the normal operation (e.g. linking a new association to the parent group).
|
|
// See https://google.aip.dev/128.
|
|
bool reconciling = 8 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Optional. User-provided description of the deployment.
|
|
// Used as additional context for the deployment.
|
|
string description = 9 [(google.api.field_behavior) = OPTIONAL];
|
|
}
|
|
|
|
// Request message for ListInterceptDeployments.
|
|
message ListInterceptDeploymentsRequest {
|
|
// Required. The parent, which owns this collection of deployments.
|
|
// Example: `projects/123456789/locations/us-central1-a`.
|
|
// See https://google.aip.dev/132 for more details.
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptDeployment"
|
|
}
|
|
];
|
|
|
|
// Optional. Requested page size. Server may return fewer items than
|
|
// requested. If unspecified, server will pick an appropriate default. See
|
|
// https://google.aip.dev/158 for more details.
|
|
int32 page_size = 2 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. A page token, received from a previous `ListInterceptDeployments`
|
|
// call. Provide this to retrieve the subsequent page. When paginating, all
|
|
// other parameters provided to `ListInterceptDeployments` must match the call
|
|
// that provided the page token. See https://google.aip.dev/158 for more
|
|
// details.
|
|
string page_token = 3 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Filter expression.
|
|
// See https://google.aip.dev/160#filtering for more details.
|
|
string filter = 4 [(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Optional. Sort expression.
|
|
// See https://google.aip.dev/132#ordering for more details.
|
|
string order_by = 5 [(google.api.field_behavior) = OPTIONAL];
|
|
}
|
|
|
|
// Response message for ListInterceptDeployments.
|
|
message ListInterceptDeploymentsResponse {
|
|
// The deployments from the specified parent.
|
|
repeated InterceptDeployment intercept_deployments = 1;
|
|
|
|
// A token that can be sent as `page_token` to retrieve the next page.
|
|
// If this field is omitted, there are no subsequent pages.
|
|
// See https://google.aip.dev/158 for more details.
|
|
string next_page_token = 2;
|
|
|
|
// Locations that could not be reached.
|
|
repeated string unreachable = 3;
|
|
}
|
|
|
|
// Request message for GetInterceptDeployment.
|
|
message GetInterceptDeploymentRequest {
|
|
// Required. The name of the deployment to retrieve.
|
|
// Format:
|
|
// projects/{project}/locations/{location}/interceptDeployments/{intercept_deployment}
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeployment"
|
|
}
|
|
];
|
|
}
|
|
|
|
// Request message for CreateInterceptDeployment.
|
|
message CreateInterceptDeploymentRequest {
|
|
// Required. The parent resource where this deployment will be created.
|
|
// Format: projects/{project}/locations/{location}
|
|
string parent = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
child_type: "networksecurity.googleapis.com/InterceptDeployment"
|
|
}
|
|
];
|
|
|
|
// Required. The ID to use for the new deployment, which will become the final
|
|
// component of the deployment's resource name.
|
|
string intercept_deployment_id = 2 [(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Required. The deployment to create.
|
|
InterceptDeployment intercept_deployment = 3
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 4 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for UpdateInterceptDeployment.
|
|
message UpdateInterceptDeploymentRequest {
|
|
// Optional. The list of fields to update.
|
|
// Fields are specified relative to the deployment
|
|
// (e.g. `description`; *not* `intercept_deployment.description`).
|
|
// See https://google.aip.dev/161 for more details.
|
|
google.protobuf.FieldMask update_mask = 1
|
|
[(google.api.field_behavior) = OPTIONAL];
|
|
|
|
// Required. The deployment to update.
|
|
InterceptDeployment intercept_deployment = 2
|
|
[(google.api.field_behavior) = REQUIRED];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 3 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Request message for DeleteInterceptDeployment.
|
|
message DeleteInterceptDeploymentRequest {
|
|
// Required. Name of the resource
|
|
string name = 1 [
|
|
(google.api.field_behavior) = REQUIRED,
|
|
(google.api.resource_reference) = {
|
|
type: "networksecurity.googleapis.com/InterceptDeployment"
|
|
}
|
|
];
|
|
|
|
// Optional. A unique identifier for this request. Must be a UUID4.
|
|
// This request is only idempotent if a `request_id` is provided.
|
|
// See https://google.aip.dev/155 for more details.
|
|
string request_id = 2 [
|
|
(google.api.field_info).format = UUID4,
|
|
(google.api.field_behavior) = OPTIONAL
|
|
];
|
|
}
|
|
|
|
// Details about intercept in a specific cloud location.
|
|
message InterceptLocation {
|
|
// The current state of a resource in the location.
|
|
enum State {
|
|
// State not set (this is not a valid state).
|
|
STATE_UNSPECIFIED = 0;
|
|
|
|
// The resource is ready and in sync in the location.
|
|
ACTIVE = 1;
|
|
|
|
// The resource is out of sync in the location.
|
|
// In most cases, this is a result of a transient issue within the system
|
|
// (e.g. an inaccessible location) and the system is expected to recover
|
|
// automatically.
|
|
OUT_OF_SYNC = 2;
|
|
}
|
|
|
|
// Output only. The cloud location, e.g. "us-central1-a" or "asia-south1".
|
|
string location = 1 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
|
|
// Output only. The current state of the association in this location.
|
|
State state = 2 [(google.api.field_behavior) = OUTPUT_ONLY];
|
|
}
|