All Products
Search
Document Center

Edge Security Acceleration:UpdateUserWafRuleset

Last Updated:Jan 16, 2026

Modifies the WAF ruleset configuration for a specified instance, including its position, name, and other properties.

Operation description

Request description

  • This operation updates an existing WAF ruleset. You can modify the position, name, description, status, and expression of the ruleset.

  • Include only the parameters that you want to modify. Omit parameters that you do not want to change.

  • Note: Before you call this operation, ensure that the InstanceId and Id values are correct. Otherwise, the request may fail.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

esa:UpdateUserWafRuleset

none

*All Resource

*

None None

Request parameters

Parameter

Type

Required

Description

Example

InstanceId

string

Yes

The instance ID.

esa-xxxxxxx

Id

integer

Yes

The WAF ruleset ID.

10000001

Position

integer

No

The position of the WAF ruleset.

1

Name

string

No

The name of the WAF ruleset.

example

Description

string

No

The description of the WAF ruleset.

example

Status

string

No

The status of the WAF ruleset.

on

Expression

string

No

The expression of the WAF ruleset.

ip.src == 1.1.1.1

Shared WafBatchRuleShared

No

The shared configuration of the WAF ruleset.

Rules

array

No

A list of rule configurations in the WAF ruleset.

[ { "Id": 20000001, "Name": "rule1", "Expression": "ip.src eq 1.1.1.1", "Action": "deny" }

WafRuleConfig

No

A rule configuration in the WAF ruleset.

Response elements

Element

Type

Description

Example

object

The response schema.

RequestId

string

The request ID.

xxxx-xxxx-xxxx-xxxx

Examples

Success response

JSON format

{
  "RequestId": "xxxx-xxxx-xxxx-xxxx"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidParameter The specified parameter is invalid. The specified parameter is invalid.
400 InstanceNotExist The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account. The instance does not exist. Check whether the specified instance ID is correct or whether the instance belongs to your account.
400 InternalException Failed to call the service. Try again later or contact technical support. Failed to call the service. Try again later or contact technical support.
403 Rule.Config.Noncompliance The specified rule configuration does not meet the compliance requirements.Check and adjust your configurations. The specified rule configuration does not meet the compliance requirements.Check and adjust your configurations.
403 Rule.Config.Malformed The format of the rule configuration is invalid.Check the configuration for syntax errors or structural inconsistencies and correct them to meet the requirements. The format of the rule configuration is invalid.Check the configuration for syntax errors or structural inconsistencies and correct them to meet the requirements.
403 %s.NotSupport The specified resource type %s is not supported. The specified resource type is not supported. To use this type of resource, please contact us.
403 %s.OverQuota The quantity of %s exceeds the quota. The amount of this resource exceeds the quota. If you need to apply for more quota, please contact us.
403 %s.WrongValueMatched The value of specified parameter %s can not pass the matching check. The value of the specified parameter can not pass the matching check. If you determine that you need to use this parameter value, please contact us.
403 Ruleset.NotExist The specified rule set does not exist or has not been registered in the system.Check whether the specified rule set identifier is valid and matches a rule set that has been correctly defined and maintained by the system's rule set registry.If you want to add a new rule set, make sure that the creation and registration process is complete to bring the rule set into effect. The specified rule set does not exist or has not been registered in the system.Check whether the specified rule set identifier is valid and matches a rule set that has been correctly defined and maintained by the system's rule set registry.If you want to add a new rule set, make sure that the creation and registration process is complete to bring the rule set into effect.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.