Class: Google::Apis::NetworkservicesV1::AuthzExtension

Inherits:
Object
  • Object
show all
Includes:
Core::Hashable, Core::JsonObjectSupport
Defined in:
lib/google/apis/networkservices_v1/classes.rb,
lib/google/apis/networkservices_v1/representations.rb,
lib/google/apis/networkservices_v1/representations.rb

Overview

AuthzExtension is a resource that allows traffic forwarding to a callout backend service to make an authorization decision.

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(**args) ⇒ AuthzExtension

Returns a new instance of AuthzExtension.



554
555
556
# File 'lib/google/apis/networkservices_v1/classes.rb', line 554

def initialize(**args)
   update!(**args)
end

Instance Attribute Details

#authorityString

Optional. The :authority header in the gRPC request sent from Envoy to the extension service. It is required when the service field points to a backend service. Corresponds to the JSON property authority

Returns:

  • (String)


439
440
441
# File 'lib/google/apis/networkservices_v1/classes.rb', line 439

def authority
  @authority
end

#create_timeString

Output only. The timestamp when the resource was created. Corresponds to the JSON property createTime

Returns:

  • (String)


444
445
446
# File 'lib/google/apis/networkservices_v1/classes.rb', line 444

def create_time
  @create_time
end

#descriptionString

Optional. A human-readable description of the resource. Corresponds to the JSON property description

Returns:

  • (String)


449
450
451
# File 'lib/google/apis/networkservices_v1/classes.rb', line 449

def description
  @description
end

#fail_openBoolean Also known as: fail_open?

Optional. Determines how the proxy behaves if the call to the extension fails or times out. When set to TRUE, request or response processing continues without error. Any subsequent extensions in the extension chain are also executed. When set to FALSE or the default setting of FALSE is used, one of the following happens: * If response headers have not been delivered to the downstream client, a generic 500 error is returned to the client. The error response can be tailored by configuring a custom error response in the load balancer. * If response headers have been delivered, then the HTTP stream to the downstream client is reset. Corresponds to the JSON property failOpen

Returns:

  • (Boolean)


462
463
464
# File 'lib/google/apis/networkservices_v1/classes.rb', line 462

def fail_open
  @fail_open
end

#forward_attributesArray<String>

Optional. List of the Envoy attributes to forward to the extension server. The attributes provided here are included as part of the ProcessingRequest. attributes field (of type map), where the keys are the attribute names. Refer to the documentation for the names of attributes that can be forwarded. If omitted, no attributes are sent. Each element is a string indicating the attribute name. Corresponds to the JSON property forwardAttributes

Returns:

  • (Array<String>)


474
475
476
# File 'lib/google/apis/networkservices_v1/classes.rb', line 474

def forward_attributes
  @forward_attributes
end

#forward_headersArray<String>

Optional. List of the HTTP headers to forward to the extension (from the client). If omitted, all headers are sent. Each element is a string indicating the header name. Corresponds to the JSON property forwardHeaders

Returns:

  • (Array<String>)


481
482
483
# File 'lib/google/apis/networkservices_v1/classes.rb', line 481

def forward_headers
  @forward_headers
end

#labelsHash<String,String>

Optional. Set of labels associated with the AuthzExtension resource. The format must comply with the requirements for labels for Google Cloud resources. Corresponds to the JSON property labels

Returns:

  • (Hash<String,String>)


488
489
490
# File 'lib/google/apis/networkservices_v1/classes.rb', line 488

def labels
  @labels
end

#load_balancing_schemeString

Optional. All backend services and forwarding rules referenced by this extension must share the same load balancing scheme. The supported values are INTERNAL_MANAGED and EXTERNAL_MANAGED. You can omit this field for AuthzExtensions resources that don't reference a backend service. For more information, see Backend services overview. Corresponds to the JSON property loadBalancingScheme

Returns:

  • (String)


498
499
500
# File 'lib/google/apis/networkservices_v1/classes.rb', line 498

def load_balancing_scheme
  @load_balancing_scheme
end

#metadataHash<String,Object>

Optional. The metadata provided here is included as part of the metadata_context (of type google.protobuf.Struct) in the ProcessingRequest message sent to the extension server. The metadata is available under the namespace com.google.authz_extension.. The following variables are supported in the metadata Struct: forwarding_rule_id - substituted with the forwarding rule's fully qualified resource name. Corresponds to the JSON property metadata

Returns:

  • (Hash<String,Object>)


508
509
510
# File 'lib/google/apis/networkservices_v1/classes.rb', line 508

def 
  @metadata
end

#nameString

Required. Identifier. Name of the AuthzExtension resource in the following format: projects/project/locations/location/authzExtensions/ authz_extension`. Corresponds to the JSON propertyname`

Returns:

  • (String)


515
516
517
# File 'lib/google/apis/networkservices_v1/classes.rb', line 515

def name
  @name
end

#serviceString

Required. The reference to the service that runs the extension. To configure a callout extension: For global AuthzExtension, service must be a fully- qualified reference to a backend service in the format: https://www.googleapis. com/compute/v1/projects/project/global/backendServices/backendService. For regional AuthzExtension, `service` must be a fully-qualified reference to one of the following: * a [backend service](https://cloud.google.com/compute/ docs/reference/rest/v1/backendServices) in the format: `https://www.googleapis. com/compute/v1/projects/`project`/regions/`region`/backendServices/` backendService. * a fully qualified domain name that can be resolved by the Google Cloud DNS. * iap.googleapis.com and it can only be referenced by an AuthzPolicy with the policyProfile set to REQUEST_AUTHZ. * modelarmor..rep. googleapis.com and it can only be referenced by an AuthzPolicy with the policyProfile set to CONTENT_AUTHZ. Corresponds to the JSON property service

Returns:

  • (String)


533
534
535
# File 'lib/google/apis/networkservices_v1/classes.rb', line 533

def service
  @service
end

#timeoutString

Required. Specifies the timeout for each individual message on the stream. The timeout must be between 10-10000 milliseconds. Corresponds to the JSON property timeout

Returns:

  • (String)


539
540
541
# File 'lib/google/apis/networkservices_v1/classes.rb', line 539

def timeout
  @timeout
end

#update_timeString

Output only. The timestamp when the resource was updated. Corresponds to the JSON property updateTime

Returns:

  • (String)


544
545
546
# File 'lib/google/apis/networkservices_v1/classes.rb', line 544

def update_time
  @update_time
end

#wire_formatString

Optional. The format of communication supported by the callout extension. This field is supported only for regional AuthzExtension resources. If not specified, the default value EXT_PROC_GRPC is used. Global AuthzExtension resources use the EXT_PROC_GRPC wire format. Corresponds to the JSON property wireFormat

Returns:

  • (String)


552
553
554
# File 'lib/google/apis/networkservices_v1/classes.rb', line 552

def wire_format
  @wire_format
end

Instance Method Details

#update!(**args) ⇒ Object

Update properties of this object



559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
# File 'lib/google/apis/networkservices_v1/classes.rb', line 559

def update!(**args)
  @authority = args[:authority] if args.key?(:authority)
  @create_time = args[:create_time] if args.key?(:create_time)
  @description = args[:description] if args.key?(:description)
  @fail_open = args[:fail_open] if args.key?(:fail_open)
  @forward_attributes = args[:forward_attributes] if args.key?(:forward_attributes)
  @forward_headers = args[:forward_headers] if args.key?(:forward_headers)
  @labels = args[:labels] if args.key?(:labels)
  @load_balancing_scheme = args[:load_balancing_scheme] if args.key?(:load_balancing_scheme)
  @metadata = args[:metadata] if args.key?(:metadata)
  @name = args[:name] if args.key?(:name)
  @service = args[:service] if args.key?(:service)
  @timeout = args[:timeout] if args.key?(:timeout)
  @update_time = args[:update_time] if args.key?(:update_time)
  @wire_format = args[:wire_format] if args.key?(:wire_format)
end