Invokes the RemoveEntriesFromAcl operation to delete IP entries from an access control policy group.
Operation description
- RemoveEntriesFromAcl is an asynchronous operation. After a request is sent, the system returns a request ID, but the IP entries are not yet deleted. The deletion node continues to run in the background. You can invoke GetAcl or ListAcls to query the status of the access control policy group:
If the access control policy group is in the configuring state, the IP entries are being deleted. In this state, you can only execute query operations and cannot execute other operations.
If the access control policy group is in the active state, the IP entries are deleted.
RemoveEntriesFromAcl does not support concurrent deletion of IP entries from access control policy groups within the same Alibaba Cloud Global Accelerator (GA) instance.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ga:RemoveEntriesFromAcl |
update |
*Acl
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID of the Alibaba Cloud Global Accelerator (GA) instance. Set the value to cn-hangzhou. |
cn-hangzhou |
| AclId |
string |
Yes |
The access control policy group ID. |
nacl-hp34s2h0xx1ht4nwo**** |
| AclEntries |
array<object> |
Yes |
The access control policy group entries to delete. You can delete up to 50 entries at a time. |
|
|
object |
No |
The access control policy group entries to delete. You can delete up to 50 entries at a time. |
||
| Entry |
string |
No |
The access control policy group entry, which is an IP address or CIDR block entry. You can delete up to 50 entries at a time. Note
This parameter is required. |
10.0.XX.XX/24 |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The client token can contain only ASCII characters. Note
If you do not specify this parameter, the system automatically uses the RequestId value as the ClientToken value. The RequestId value is different for each API request. |
593B0448-D13E-4C56-AC0D-FDF0FDE0E9A3 |
| DryRun |
boolean |
No |
Specifies whether to perform a dry run. Valid values:
|
false |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
64ADAB1E-0B7F-4FD8-A404-3BECC0E9CCFF |
| AclId |
string |
The access control policy group ID. |
nacl-hp34s2h0xx1ht4nwo**** |
Examples
Success response
JSON format
{
"RequestId": "64ADAB1E-0B7F-4FD8-A404-3BECC0E9CCFF",
"AclId": "nacl-hp34s2h0xx1ht4nwo****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | NotExist.Acl | acl %s is not exist | The ACL %s does not exist. |
| 400 | StateError.Acl | acl state %s is illegal | The status of the ACL %s is invalid. |
| 400 | NotExist.AclEntries | acl entries is not exist |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.