View a markdown version of this page

GetPolicy - AWS Network Security Manager

GetPolicy

Retrieves the details of the specified policy.

Request Syntax

GET /policies/policyIdentifier HTTP/1.1

URI Request Parameters

The request uses the following URI parameters.

policyIdentifier

The identifier of the policy. This is the policy's Amazon Resource Name (ARN).

Length Constraints: Minimum length of 1. Maximum length of 1010.

Required: Yes

Request Body

The request does not have a request body.

Response Syntax

HTTP/1.1 200 Content-type: application/json { "associatedTemplateAndRuleList": [ { ... } ], "firewallType": "string", "hasPublishedVersion": boolean, "isSnapshot": boolean, "policyArn": "string", "policyConfiguration": { "remediationEnabled": boolean, "resourcesCleanUp": boolean, "wafConfig": { "conflictResolution": "string", "existingCustomerWebACLResolution": "string" } }, "policyDescription": "string", "policyId": "string", "policyName": "string", "priority": number, "status": "string", "updatedAt": "string", "updateToken": "string", "version": "string" }

Response Elements

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

associatedTemplateAndRuleList

The templates and rules associated with the policy. For AWS WAF policies, this list contains 1 to 100 templates or rules, of which at most 2 can be templates. For AWS Shield Advanced policies, this list is empty.

Type: Array of AssociatedTemplateOrRule objects

Array Members: Minimum number of 0 items. Maximum number of 100 items.

firewallType

The firewall type associated with the resource.

Type: String

Valid Values: WAF | SHIELD_ADVANCED

hasPublishedVersion

Specifies whether a published version of the resource exists.

Type: Boolean

isSnapshot

Specifies whether the resource is a snapshot of a published version.

Type: Boolean

policyArn

The Amazon Resource Name (ARN) of the policy.

Type: String

Length Constraints: Minimum length of 20. Maximum length of 1010.

Pattern: arn(:[a-z0-9]+([.-][a-z0-9]+)*){2}(:([a-z0-9]+([.-][a-z0-9]+)*)?){2}:(.+)

policyConfiguration

The configuration settings that control the policy's behavior, including remediation and firewall-type-specific settings.

Type: PolicyConfiguration object

policyDescription

A description of the policy.

Type: String

Length Constraints: Minimum length of 0. Maximum length of 256.

Pattern: [a-zA-Z0-9 _.:/=+\-@]*

policyId

The service-generated id of the policy.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 64.

Pattern: [a-z0-9]{1,64}

policyName

The name of the policy.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 128.

Pattern: [a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*

priority

The priority of the resource. A lower number indicates a higher priority.

Type: Integer

Valid Range: Minimum value of 1.

status

The current status of the resource: DRAFT (unpublished, editable) or ACTIVE (published, in use).

Type: String

Valid Values: DRAFT | ACTIVE | DISABLED

updatedAt

The time when the resource was last updated.

Type: Timestamp

updateToken

A token used for optimistic concurrency control. Each read and write returns an updateToken. Provide the most recent value on your next update to detect and prevent conflicting concurrent modifications.

Type: String

Length Constraints: Fixed length of 36.

Pattern: ([0-9a-f]{8})-([0-9a-f]{4}-){3}([0-9a-f]{12})

version

The version of the resource.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 10.

Pattern: [1-9][0-9]*

Errors

For information about the errors that are common to all actions, see Common Error Types.

AccessDeniedException

You do not have sufficient permissions to perform this action.

HTTP Status Code: 403

InternalServerException

The request processing failed because of an internal error in the service. This is a retryable error.

HTTP Status Code: 500

ResourceNotFoundException

The specified resource was not found. Verify that the resource identifier is correct and that the resource exists, then try your request again.

resourceId

The ID of the resource that could not be found.

resourceType

The type of the resource that could not be found.

HTTP Status Code: 404

ThrottlingException

The request was denied because of request throttling. Reduce your request rate and try again.

retryAfterSeconds

The number of seconds to wait before retrying the request.

HTTP Status Code: 429

ValidationException

The request failed validation. For details, see the reason and fieldList members of the response.

fieldList

The list of request fields that failed validation, if any.

reason

The reason that the request failed validation.

HTTP Status Code: 400

See Also

For more information about using this API in one of the language-specific AWS SDKs, see the following: