CreateRule
Creates a rule. A rule defines a network security configuration to enforce, such as an AWS WAF rule group or configuration data. Use isPublished to create the rule in published (ACTIVE) or draft (DRAFT) state.
Request Syntax
POST /rules HTTP/1.1
Content-type: application/json
{
"clientToken": "string",
"configuration": JSON value,
"firewallType": "string",
"isPublished": boolean,
"ruleDescription": "string",
"ruleName": "string",
"ruleType": "string",
"tags": {
"string" : "string"
}
}
URI Request Parameters
The request does not use any URI parameters.
Request Body
The request accepts the following data in JSON format.
- clientToken
-
A unique, case-sensitive token that you provide to ensure that the operation completes no more than one time. If you retry a request with the same client token and the same parameters, the service returns the result of the original successful request.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[\x21-\x7E]+Required: No
- configuration
-
The firewall configuration for the rule, as a JSON document. The structure depends on the rule's firewall type and rule type. For an AWS WAF
INSPECTIONrule, provide an AWS WAF rule group. For an AWS WAFCONFIGURATIONrule, provide a single web ACL setting, such asDefaultActionorVisibilityConfig; usewafConfigDataTypeto declare which setting the document contains. For the schema of each setting and complete examples, see Writing rule configurations in the AWS Network Security Manager Developer Guide.Type: JSON value
Required: Yes
- firewallType
-
The firewall type associated with the resource.
Type: String
Valid Values:
WAFRequired: Yes
- isPublished
-
Specifies whether to publish the resource. When
true, the resource is saved in published (ACTIVE) state. Whenfalse, it is saved as a draft (DRAFT). Default:true.Type: Boolean
Required: No
- ruleDescription
-
A description of the rule.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 256.
Pattern:
[a-zA-Z0-9 _.:/=+\-@]*Required: No
- ruleName
-
The name of the rule.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*Required: Yes
- ruleType
-
The type of the rule.
CONFIGURATIONrules contain firewall settings, andINSPECTIONrules contain rule groups.Type: String
Valid Values:
CONFIGURATION | INSPECTIONRequired: Yes
-
The tags to add to the resource when it is created.
Type: String to string map
Map Entries: Minimum number of 0 items. Maximum number of 200 items.
Key Length Constraints: Minimum length of 1. Maximum length of 128.
Key Pattern:
([\p{L}\p{Z}\p{N}_.:/=+\-@]*)Value Length Constraints: Minimum length of 0. Maximum length of 256.
Required: No
Response Syntax
HTTP/1.1 201
Content-type: application/json
{
"configuration": JSON value,
"firewallType": "string",
"hasPublishedVersion": boolean,
"isSnapshot": boolean,
"ruleArn": "string",
"ruleDescription": "string",
"ruleId": "string",
"ruleName": "string",
"ruleType": "string",
"status": "string",
"updatedAt": "string",
"updateToken": "string",
"version": "string"
}
Response Elements
If the action is successful, the service sends back an HTTP 201 response.
The following data is returned in JSON format by the service.
- configuration
-
The firewall configuration for the rule, as a JSON document. The structure depends on the rule's firewall type and rule type.
Type: JSON value
- firewallType
-
The firewall type associated with the resource.
Type: String
Valid Values:
WAF - hasPublishedVersion
-
Specifies whether a published version of the resource exists.
Type: Boolean
- isSnapshot
-
Specifies whether the resource is a snapshot of a published version.
Type: Boolean
- ruleArn
-
The Amazon Resource Name (ARN) of the rule.
Type: String
Length Constraints: Minimum length of 20. Maximum length of 1010.
Pattern:
arn(:[a-z0-9]+([.-][a-z0-9]+)*){2}(:([a-z0-9]+([.-][a-z0-9]+)*)?){2}:(.+) - ruleDescription
-
A description of the rule.
Type: String
Length Constraints: Minimum length of 0. Maximum length of 256.
Pattern:
[a-zA-Z0-9 _.:/=+\-@]* - ruleId
-
The service-generated id of the rule.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 64.
Pattern:
[a-z0-9]{1,64} - ruleName
-
The name of the rule.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 128.
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]* - ruleType
-
The type of the rule.
CONFIGURATIONrules contain firewall settings, andINSPECTIONrules contain rule groups.Type: String
Valid Values:
CONFIGURATION | INSPECTION - status
-
The current status of the resource:
DRAFT(unpublished, editable) orACTIVE(published, in use).Type: String
Valid Values:
DRAFT | ACTIVE | DISABLED - updatedAt
-
The time when the resource was last updated.
Type: Timestamp
- updateToken
-
A token used for optimistic concurrency control. Each read and write returns an
updateToken. Provide the most recent value on your next update to detect and prevent conflicting concurrent modifications.Type: String
Length Constraints: Fixed length of 36.
Pattern:
([0-9a-f]{8})-([0-9a-f]{4}-){3}([0-9a-f]{12}) - version
-
The version of the resource.
Type: String
Length Constraints: Minimum length of 1. Maximum length of 10.
Pattern:
[1-9][0-9]*
Errors
For information about the errors that are common to all actions, see Common Error Types.
- AccessDeniedException
-
You do not have sufficient permissions to perform this action.
HTTP Status Code: 403
- ConflictException
-
The request conflicts with the current state of the resource. For example, the resource was modified concurrently, or it is in a state that does not allow the requested operation.
- resourceId
-
The ID of the resource that is in conflict with the request.
- resourceType
-
The type of the resource that is in conflict with the request.
HTTP Status Code: 409
- InternalServerException
-
The request processing failed because of an internal error in the service. This is a retryable error.
HTTP Status Code: 500
- ServiceQuotaExceededException
-
The request would exceed a service quota.
- quotaCode
-
The code that identifies the service quota that was exceeded.
- resourceId
-
The ID of the resource associated with the quota that was exceeded.
- resourceType
-
The type of the resource associated with the quota that was exceeded.
- serviceCode
-
The code for the AWS service that owns the quota that was exceeded.
HTTP Status Code: 402
- ServiceUnavailableException
-
The service is temporarily unavailable. This is a retryable error.
- retryAfterSeconds
-
The number of seconds to wait before retrying the request.
HTTP Status Code: 503
- TagPolicyViolationException
-
The request violates a tag policy that is in effect for the account or organization.
HTTP Status Code: 400
- ThrottlingException
-
The request was denied because of request throttling. Reduce your request rate and try again.
- retryAfterSeconds
-
The number of seconds to wait before retrying the request.
HTTP Status Code: 429
- ValidationException
-
The request failed validation. For details, see the
reasonandfieldListmembers of the response.- fieldList
-
The list of request fields that failed validation, if any.
- reason
-
The reason that the request failed validation.
HTTP Status Code: 400
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: