service_gateways
Creates, updates, deletes, gets or lists a service_gateways resource.
Overview​
| Name | service_gateways |
| Type | Resource |
| Id | oci.network.service_gateways |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The service gateway was retrieved.
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the service gateway. |
blockTraffic | boolean | Whether the service gateway blocks all traffic through it. The default is false. When this is true, traffic is not routed to any services, regardless of route rules. Example: true |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment that contains the service gateway. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
lifecycleState | string | The service gateway's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
routeTableId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the route table the service gateway is using. For information about why you would associate a route table with a service gateway, see [Transit Routing: Private Access to Oracle Services](/iaas/Content/Network/Tasks/transitroutingoracleservices.htm). |
services | array | List of the [Service](#/en/iaas/latest/Service/) objects enabled for this service gateway. The list can be empty. You can enable a particular Service by using [AttachServiceId](#/en/iaas/latest/ServiceGateway/AttachServiceId) or [UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway). |
timeCreated | string (date-time) | The date and time the service gateway was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN the service gateway belongs to. |
Represents a router that lets your VCN privately access specific Oracle services such as Object<br />Storage without exposing the VCN to the public internet. Traffic leaving the VCN and destined<br />for a supported Oracle service (use the [ListServices](#/en/iaas/latest/Service/ListServices) operation to<br />find available service CIDR labels) is routed through the service gateway and does not traverse the internet.<br />The instances in the VCN do not need to have public IP addresses nor be in a public subnet. The VCN does not<br />need an internet gateway for this traffic. For more information, see<br />[Access to Oracle Services: Service Gateway](/iaas/Content/Network/Tasks/servicegateway.htm).<br /><br />To use any of the API operations, you must be authorized in an IAM policy. If you're not authorized,<br />talk to an administrator. If you're an administrator who needs to write policies to give users access, see<br />[Getting Started with Policies](/iaas/Content/Identity/Concepts/policygetstarted.htm).<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the service gateway. |
blockTraffic | boolean | Whether the service gateway blocks all traffic through it. The default is false. When this is true, traffic is not routed to any services, regardless of route rules. Example: true |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment that contains the service gateway. |
definedTags | object | Defined tags for this resource. Each key is predefined and scoped to a namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Operations": {"CostCenter": "42"}} |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
freeformTags | object | Free-form tags for this resource. Each tag is a simple key-value pair with no predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm). Example: {"Department": "Finance"} |
lifecycleState | string | The service gateway's current state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
routeTableId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the route table the service gateway is using. For information about why you would associate a route table with a service gateway, see [Transit Routing: Private Access to Oracle Services](/iaas/Content/Network/Tasks/transitroutingoracleservices.htm). |
services | array | List of the [Service](#/en/iaas/latest/Service/) objects enabled for this service gateway. The list can be empty. You can enable a particular Service by using [AttachServiceId](#/en/iaas/latest/ServiceGateway/AttachServiceId) or [UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway). |
timeCreated | string (date-time) | The date and time the service gateway was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN the service gateway belongs to. |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | serviceGatewayId, region | Gets the specified service gateway's information. | |
list | select | compartmentId, region | vcnId, limit, page, sortBy, sortOrder, lifecycleState | Lists the service gateways in the specified compartment. You may optionally specify a VCN OCID<br />to filter the results by VCN.<br /> |
attach | insert | serviceGatewayId, region, serviceId | if-match | Adds the specified [Service](#/en/iaas/latest/Service/) to the list of enabled<br />Service objects for the specified gateway. You must also set up a route rule with the<br />cidrBlock of the Service as the rule's destination and the service gateway as the rule's<br />target. See [Route Table](#/en/iaas/latest/RouteTable/).<br /><br />Note: The AttachServiceId operation is an easy way to add an individual Service to<br />the service gateway. Compare it with<br />[UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway), which replaces<br />the entire existing list of enabled Service objects with the list that you provide in the<br />Update call.<br /> |
create | insert | region, compartmentId, vcnId, services | opc-retry-token | Creates a new service gateway in the specified compartment.<br /><br />For the purposes of access control, you must provide the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment where you want<br />the service gateway to reside. For more information about compartments and access control, see<br />[Overview of the IAM Service](/iaas/Content/Identity/Concepts/overview.htm).<br />For information about OCIDs, see [Resource Identifiers](/iaas/Content/General/Concepts/identifiers.htm).<br /><br />You may optionally specify a display name for the service gateway, otherwise a default is provided.<br />It does not have to be unique, and you can change it. Avoid entering confidential information.<br /><br />Use the [ListServices](#/en/iaas/latest/Service/ListServices) operation to find service CIDR labels<br />available in the region.<br /> |
update | update | serviceGatewayId, region | if-match | Updates the specified service gateway. The information you provide overwrites the existing<br />attributes of the gateway.<br /> |
delete | delete | serviceGatewayId, region | if-match | Deletes the specified service gateway. There must not be a route table that lists the service<br />gateway as a target.<br /> |
change_compartment | exec | serviceGatewayId, region, compartmentId | opc-request-id, opc-retry-token | Moves a service gateway into a different compartment within the same tenancy. For information<br />about moving resources between compartments, see<br />[Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br /> |
detach_service_id | exec | serviceGatewayId, region, serviceId | if-match | Removes the specified [Service](#/en/iaas/latest/Service/) from the list of enabled<br />Service objects for the specified gateway. You do not need to remove any route<br />rules that specify this Service object's cidrBlock as the destination CIDR. However, consider<br />removing the rules if your intent is to permanently disable use of the Service through this<br />service gateway.<br /><br />Note: The DetachServiceId operation is an easy way to remove an individual Service from<br />the service gateway. Compare it with<br />[UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway), which replaces<br />the entire existing list of enabled Service objects with the list that you provide in the<br />Update call. UpdateServiceGateway also lets you block all traffic through the service<br />gateway without having to remove each of the individual Service objects.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
serviceGatewayId | string | The service gateway's [OCID](/iaas/Content/General/Concepts/identifiers.htm). |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
lifecycleState | string | A filter to return only resources that match the given lifecycle state. The state value is case-insensitive. |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50 |
opc-request-id | string | Unique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
opc-retry-token | string | A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected). |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
sortBy | string | The field to sort by. You can provide one sort order (sortOrder). Default order for TIMECREATED is descending. Default order for DISPLAYNAME is ascending. The DISPLAYNAME sort order is case sensitive. Note: In general, some "List" operations (for example, ListInstances) let you optionally filter by availability domain if the scope of the resource type is within a single availability domain. If you call one of these "List" operations without specifying an availability domain, the resources are grouped by availability domain, then sorted. |
sortOrder | string | The sort order to use, either ascending (ASC) or descending (DESC). The DISPLAYNAME sort order is case sensitive. |
vcnId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN. |
SELECT examples​
- get
- list
Gets the specified service gateway's information.
SELECT
id,
blockTraffic,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
routeTableId,
services,
timeCreated,
vcnId
FROM oci.network.service_gateways
WHERE serviceGatewayId = '{{ serviceGatewayId }}' -- required
AND region = '{{ region }}' -- required
;
Lists the service gateways in the specified compartment. You may optionally specify a VCN OCID<br />to filter the results by VCN.<br />
SELECT
id,
blockTraffic,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
routeTableId,
services,
timeCreated,
vcnId
FROM oci.network.service_gateways
WHERE compartmentId = '{{ compartmentId }}' -- required
AND region = '{{ region }}' -- required
AND vcnId = '{{ vcnId }}'
AND limit = '{{ limit }}'
AND page = '{{ page }}'
AND sortBy = '{{ sortBy }}'
AND sortOrder = '{{ sortOrder }}'
AND lifecycleState = '{{ lifecycleState }}'
;
INSERT examples​
- attach
- create
- Manifest
Adds the specified [Service](#/en/iaas/latest/Service/) to the list of enabled<br />Service objects for the specified gateway. You must also set up a route rule with the<br />cidrBlock of the Service as the rule's destination and the service gateway as the rule's<br />target. See [Route Table](#/en/iaas/latest/RouteTable/).<br /><br />Note: The AttachServiceId operation is an easy way to add an individual Service to<br />the service gateway. Compare it with<br />[UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway), which replaces<br />the entire existing list of enabled Service objects with the list that you provide in the<br />Update call.<br />
INSERT INTO oci.network.service_gateways (
serviceId,
serviceGatewayId,
region,
if-match
)
SELECT
'{{ serviceId }}' /* required */,
'{{ serviceGatewayId }}',
'{{ region }}',
'{{ if-match }}'
RETURNING
id,
blockTraffic,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
routeTableId,
services,
timeCreated,
vcnId
;
Creates a new service gateway in the specified compartment.<br /><br />For the purposes of access control, you must provide the [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment where you want<br />the service gateway to reside. For more information about compartments and access control, see<br />[Overview of the IAM Service](/iaas/Content/Identity/Concepts/overview.htm).<br />For information about OCIDs, see [Resource Identifiers](/iaas/Content/General/Concepts/identifiers.htm).<br /><br />You may optionally specify a display name for the service gateway, otherwise a default is provided.<br />It does not have to be unique, and you can change it. Avoid entering confidential information.<br /><br />Use the [ListServices](#/en/iaas/latest/Service/ListServices) operation to find service CIDR labels<br />available in the region.<br />
INSERT INTO oci.network.service_gateways (
compartmentId,
definedTags,
displayName,
freeformTags,
routeTableId,
services,
vcnId,
region,
opc-retry-token
)
SELECT
'{{ compartmentId }}' /* required */,
'{{ definedTags }}',
'{{ displayName }}',
'{{ freeformTags }}',
'{{ routeTableId }}',
'{{ services }}' /* required */,
'{{ vcnId }}' /* required */,
'{{ region }}',
'{{ opc-retry-token }}'
RETURNING
id,
blockTraffic,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
routeTableId,
services,
timeCreated,
vcnId
;
# Description fields are for documentation purposes
- name: service_gateways
props:
- name: serviceGatewayId
value: "{{ serviceGatewayId }}"
description: Required parameter for the service_gateways resource.
- name: region
value: "{{ region }}"
description: Required parameter for the service_gateways resource.
- name: serviceId
value: "{{ serviceId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the [Service](#/en/iaas/latest/Service/).
- name: compartmentId
value: "{{ compartmentId }}"
description: |
The [OCID](/Content/General/Concepts/identifiers.htm) of the compartment to contain the service gateway.
- name: definedTags
value: "{{ definedTags }}"
description: |
Defined tags for this resource. Each key is predefined and scoped to a
namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Operations": {"CostCenter": "42"}}`
- name: displayName
value: "{{ displayName }}"
description: |
A user-friendly name. Does not have to be unique, and it's changeable.
Avoid entering confidential information.
- name: freeformTags
value: "{{ freeformTags }}"
description: |
Free-form tags for this resource. Each tag is a simple key-value pair with no
predefined name, type, or namespace. For more information, see [Resource Tags](/iaas/Content/General/Concepts/resourcetags.htm).
Example: `{"Department": "Finance"}`
- name: routeTableId
value: "{{ routeTableId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the route table the service gateway will use.
If you don't specify a route table here, the service gateway is created without an associated route
table. The Networking service does NOT automatically associate the attached VCN's default route table
with the service gateway.
For information about why you would associate a route table with a service gateway, see
[Transit Routing: Private Access to Oracle Services](/iaas/Content/Network/Tasks/transitroutingoracleservices.htm).
- name: services
description: |
List of the OCIDs of the [Service](#/en/iaas/latest/Service/) objects to
enable for the service gateway. This list can be empty if you don't want to enable any
`Service` objects when you create the gateway. You can enable a `Service`
object later by using either [AttachServiceId](#/en/iaas/latest/ServiceGateway/AttachServiceId)
or [UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway).
For each enabled `Service`, make sure there's a route rule with the `Service` object's `cidrBlock`
as the rule's destination and the service gateway as the rule's target. See
[Route Table](#/en/iaas/latest/RouteTable/).
value:
- serviceId: "{{ serviceId }}"
- name: vcnId
value: "{{ vcnId }}"
description: |
The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the VCN.
- name: if-match
value: "{{ if-match }}"
description: For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
description: For optimistic concurrency control. In the PUT or DELETE call for a resource, set the `if-match` parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
- name: opc-retry-token
value: "{{ opc-retry-token }}"
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
description: A token that uniquely identifies a request so it can be retried in case of a timeout or server error without risk of executing that same action again. Retry tokens expire after 24 hours, but can be invalidated before then due to conflicting operations (for example, if a resource has been deleted and purged from the system, then a retry of the original creation request may be rejected).
UPDATE examples​
- update
Updates the specified service gateway. The information you provide overwrites the existing<br />attributes of the gateway.<br />
UPDATE oci.network.service_gateways
SET
blockTraffic = {{ blockTraffic }},
definedTags = '{{ definedTags }}',
displayName = '{{ displayName }}',
freeformTags = '{{ freeformTags }}',
routeTableId = '{{ routeTableId }}',
services = '{{ services }}'
WHERE
serviceGatewayId = '{{ serviceGatewayId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
RETURNING
id,
blockTraffic,
compartmentId,
definedTags,
displayName,
freeformTags,
lifecycleState,
routeTableId,
services,
timeCreated,
vcnId;
DELETE examples​
- delete
Deletes the specified service gateway. There must not be a route table that lists the service<br />gateway as a target.<br />
DELETE FROM oci.network.service_gateways
WHERE serviceGatewayId = '{{ serviceGatewayId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match }}'
;
Lifecycle Methods​
- change_compartment
- detach_service_id
Moves a service gateway into a different compartment within the same tenancy. For information<br />about moving resources between compartments, see<br />[Moving Resources to a Different Compartment](/iaas/Content/Identity/Tasks/managingcompartments.htm#moveRes).<br />
EXEC oci.network.service_gateways.change_compartment
@serviceGatewayId='{{ serviceGatewayId }}' --required,
@region='{{ region }}' --required,
@opc-request-id='{{ opc-request-id }}',
@opc-retry-token='{{ opc-retry-token }}'
@@json=
'{
"compartmentId": "{{ compartmentId }}"
}'
;
Removes the specified [Service](#/en/iaas/latest/Service/) from the list of enabled<br />Service objects for the specified gateway. You do not need to remove any route<br />rules that specify this Service object's cidrBlock as the destination CIDR. However, consider<br />removing the rules if your intent is to permanently disable use of the Service through this<br />service gateway.<br /><br />Note: The DetachServiceId operation is an easy way to remove an individual Service from<br />the service gateway. Compare it with<br />[UpdateServiceGateway](#/en/iaas/latest/ServiceGateway/UpdateServiceGateway), which replaces<br />the entire existing list of enabled Service objects with the list that you provide in the<br />Update call. UpdateServiceGateway also lets you block all traffic through the service<br />gateway without having to remove each of the individual Service objects.<br />
EXEC oci.network.service_gateways.detach_service_id
@serviceGatewayId='{{ serviceGatewayId }}' --required,
@region='{{ region }}' --required,
@if-match='{{ if-match }}'
@@json=
'{
"serviceId": "{{ serviceId }}"
}'
;