Skip to main content

security_lists

Creates, updates, deletes, gets or lists a security_lists resource.

Overview​

Namesecurity_lists
TypeResource
Idoci.network.security_lists

Fields​

The following fields are returned by SELECT queries:

The security list was retrieved.

NameDatatypeDescription
idstringThe security list's Oracle Cloud ID ([OCID](/iaas/Content/General/Concepts/identifiers.htm)).
compartmentIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment containing the security list.
definedTagsobjectDefined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}}
displayNamestringA user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information.
egressSecurityRulesarrayRules for allowing egress IP packets.
freeformTagsobjectFree-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"}
ingressSecurityRulesarrayRules for allowing ingress IP packets.
lifecycleStatestringThe security list's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED)
timeCreatedstring (date-time)The date and time the security list was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z
vcnIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN the security list belongs to.

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectsecurityListId, regionGets the specified security list's information.
listselectcompartmentId, regionlimit, page, vcnId, displayName, sortBy, sortOrder, lifecycleStateLists the security lists in the specified VCN and compartment.<br />If the VCN ID is not provided, then the list includes the security lists from all VCNs in the specified compartment.<br />
createinsertregion, compartmentId, egressSecurityRules, ingressSecurityRules, vcnIdopc-retry-tokenCreates a new security list for the specified VCN. For more information<br />about security lists, see [Security Lists](/iaas/Content/Network/Concepts/securitylists.htm).<br />For information on the number of rules you can have in a security list, see<br />[Service Limits](/iaas/Content/General/Concepts/servicelimits.htm).<br /><br />For the purposes of access control, you must provide the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment where you want the security<br />list to reside. Notice that the security list doesn't have to be in the same compartment as the VCN, subnets,<br />or other Networking Service components. If you're not sure which compartment to use, put the security<br />list in the same compartment as the VCN. For more information about compartments and access control, see<br />[Overview of the IAM Service](/iaas/Content/Identity/Concepts/overview.htm). For information about OCIDs, see<br />[Resource Identifiers](/iaas/Content/General/Concepts/identifiers.htm).<br /><br />You may optionally specify a display name for the security list, otherwise a default is provided.<br />It does not have to be unique, and you can change it. Avoid entering confidential information.<br />
updateupdatesecurityListId, regionif-matchUpdates the specified security list's display name or rules.<br />Avoid entering confidential information.<br /><br />Note that the egressSecurityRules or ingressSecurityRules objects you provide replace the entire<br />existing objects.<br />
deletedeletesecurityListId, regionif-matchDeletes the specified security list, but only if it's not associated with a subnet. You can't delete<br />a VCN's default security list.<br /><br />This is an asynchronous operation. The security list's lifecycleState will change to TERMINATING temporarily<br />until the security list is completely removed.<br />
change_compartmentexecsecurityListId, region, compartmentIdopc-request-id, opc-retry-tokenMoves a security list into a different compartment within the same tenancy. For information<br />about moving resources between compartments, see<br />[Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
compartmentIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
securityListIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the security list.
displayNamestringA filter to return only resources that match the given display name exactly.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
lifecycleStatestringA filter to only return resources that match the given lifecycle state. The state value is case-insensitive.
limitintegerFor list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50
opc-request-idstringUnique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
opc-retry-tokenstringA token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
pagestringFor list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine).
sortBystringThe field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for DISPLAYNAME is ascending. The DISPLAYNAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by availability domain if the scope of the resource type is within a single availability domain. If you call one of these "List" operations without specifying an availability domain, the resources are grouped by availability domain, then sorted.
sortOrderstringThe sort order to use, either ascending (ASC) or descending (DESC). The DISPLAYNAME sort order is case sensitive.
vcnIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN.

SELECT examples​

Gets the specified security list's information.

SELECT
id,
compartmentId,
definedTags,
displayName,
egressSecurityRules,
freeformTags,
ingressSecurityRules,
lifecycleState,
timeCreated,
vcnId
FROM oci.network.security_lists
WHERE securityListId = '{{ securityListId }}' -- required
AND region = '{{ region }}' -- required
;

INSERT examples​

Creates a new security list for the specified VCN. For more information<br />about security lists, see [Security Lists](/iaas/Content/Network/Concepts/securitylists.htm).<br />For information on the number of rules you can have in a security list, see<br />[Service Limits](/iaas/Content/General/Concepts/servicelimits.htm).<br /><br />For the purposes of access control, you must provide the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment where you want the security<br />list to reside. Notice that the security list doesn't have to be in the same compartment as the VCN, subnets,<br />or other Networking Service components. If you're not sure which compartment to use, put the security<br />list in the same compartment as the VCN. For more information about compartments and access control, see<br />[Overview of the IAM Service](/iaas/Content/Identity/Concepts/overview.htm). For information about OCIDs, see<br />[Resource Identifiers](/iaas/Content/General/Concepts/identifiers.htm).<br /><br />You may optionally specify a display name for the security list, otherwise a default is provided.<br />It does not have to be unique, and you can change it. Avoid entering confidential information.<br />

INSERT INTO oci.network.security_lists (
compartmentId,
definedTags,
displayName,
egressSecurityRules,
freeformTags,
ingressSecurityRules,
vcnId,
region,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ displayName }}',
'{{ egressSecurityRules }}' /* required */,
'{{ freeformTags }}',
'{{ ingressSecurityRules }}' /* required */,
'{{ vcnId }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
compartmentId,
definedTags,
displayName,
egressSecurityRules,
freeformTags,
ingressSecurityRules,
lifecycleState,
timeCreated,
vcnId
;

UPDATE examples​

Updates the specified security list's display name or rules.<br />Avoid entering confidential information.<br /><br />Note that the egressSecurityRules or ingressSecurityRules objects you provide replace the entire<br />existing objects.<br />

UPDATE oci.network.security_lists
SET
definedTags = '{{ definedTags }}',
displayName = '{{ displayName }}',
egressSecurityRules = '{{ egressSecurityRules }}',
freeformTags = '{{ freeformTags }}',
ingressSecurityRules = '{{ ingressSecurityRules }}'
WHERE
securityListId = '{{ securityListId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
compartmentId,
definedTags,
displayName,
egressSecurityRules,
freeformTags,
ingressSecurityRules,
lifecycleState,
timeCreated,
vcnId;

DELETE examples​

Deletes the specified security list, but only if it's not associated with a subnet. You can't delete<br />a VCN's default security list.<br /><br />This is an asynchronous operation. The security list's lifecycleState will change to TERMINATING temporarily<br />until the security list is completely removed.<br />

DELETE FROM oci.network.security_lists
WHERE securityListId = '{{ securityListId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;

Lifecycle Methods​

Moves a security list into a different compartment within the same tenancy. For information<br />about moving resources between compartments, see<br />[Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br />

EXEC oci.network.security_lists.change_compartment
@securityListId='{{ securityListId }}' --required,
@region='{{ region }}' --required,
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"compartmentId": "{{ compartmentId }}"
}'
;