All Products
Search
Document Center

Resource Orchestration Service:ALIYUN::ThreatDetection::ContainerDefenseRule

Last Updated:Jul 05, 2026

The ALIYUN::ThreatDetection::ContainerDefenseRule type creates a defense rule for runtime programs.

Syntax

{
  "Type": "ALIYUN::ThreatDetection::ContainerDefenseRule",
  "Properties": {
    "Description": String,
    "RuleSwitch": Integer,
    "RuleId": Integer,
    "RuleAction": Integer,
    "RuleType": Integer,
    "RuleName": String,
    "Scope": List,
    "WhitelistHash": String,
    "Whitelist": Map
  }
}

Properties

Parameter

Type

Required

Editable

Description

Constraints

Description

String

No

Yes

The description of the rule.

None

RuleAction

Integer

No

Yes

The action to take when the rule is matched.

Valid values:

  • 1: alert

  • 2: block

RuleId

Integer

No

No

The unique ID for the rule.

None

RuleName

String

No

Yes

The user-defined name for the rule.

None

RuleSwitch

Integer

No

Yes

Indicates whether the rule is enabled or disabled.

Valid values:

  • 0: off

  • 1: on

RuleType

Integer

No

Yes

The rule type.

Valid values:

  • 2: User rules

Scope

List

No

Yes

The scope of the rule.

Length: 1 to 100. For more information, see Scope properties.

Whitelist

Map

No

Yes

The whitelist for the rule.

For more information, see Whitelist properties.

WhitelistHash

String

No

No

The hash of the whitelist.

None

Scope syntax

"Scope": [
  {
    "Namespaces": List,
    "ClusterId": String,
    "AllNamespace": Integer
  }
]

Scope properties

Parameter

Type

Required

Editable

Description

Constraints

AllNamespace

Integer

No

Yes

Specifies whether to include all namespaces.

Valid values:

  • 0: The rule applies to the namespaces specified in the Namespaces property.

  • 1: All namespaces are included.

ClusterId

String

No

Yes

The ID of the cluster to which the rule applies.

None

Namespaces

List

No

Yes

The namespaces to include.

Length: 1 to 100.

Whitelist syntax

"Whitelist": {
  "Path": List,
  "Image": List
}

Whitelist properties

Parameter

Type

Required

Editable

Description

Constraints

Image

List

No

Yes

The images to add to the whitelist.

None

Path

List

No

Yes

The file paths to add to the whitelist.

None

Outputs

Fn::GetAtt

  • RuleSwitch: Indicates whether the rule is on (1) or off (0).

  • Description: The description of the rule.

  • Scope: The scope of the rule.

  • RuleId: The unique ID for the rule.

  • RuleAction: The action taken when the rule is matched.

  • Whitelist: The whitelist for the rule.

  • RuleType: The rule type.

  • RuleName: The rule name.

Examples

ROSTemplateFormatVersion: '2015-09-01'
Parameters:
  RuleType:
    Type: Number
    Description:
      en: |-
        The rule type. Value:
        * 2: User Rules
    AllowedValues:
      - 2
    Default: Null
    Required: false
  Description:
    Type: String
    Description:
      en: The description of the rule.
    AssociationProperty: TextArea
    Default: Null
    Required: false
  RuleId:
    Type: Number
    Description:
      en: The rule ID.
    Default: Null
    Required: false
  Whitelist:
    Description:
      en: The whitelist for the rule.
    Required: false
    Default: Null
    Type: Json
    AssociationPropertyMetadata:
      Parameters:
        Path:
          Description:
            en: The paths to the files that need to be added to the whitelist.
          Required: false
          Default: Null
          Type: Json
          AssociationProperty: List[Parameter]
          AssociationPropertyMetadata:
            Parameter:
              Type: String
              Description:
                en: The file path to add to the whitelist.
              Default: Null
              Required: false
        Image:
          Description:
            en: The images that need to be added to the whitelist.
          Required: false
          Default: Null
          Type: Json
          AssociationProperty: List[Parameter]
          AssociationPropertyMetadata:
            Parameter:
              Type: String
              Description:
                en: The image to add to the whitelist.
              Default: Null
              Required: false
  RuleAction:
    Type: Number
    Description:
      en: |-
        The action that is performed when the rule is matched. Valid values:
        - **1**: alert
        - **2**: block
    AllowedValues:
      - 1
      - 2
    Default: Null
    Required: false
  RuleName:
    Type: String
    Description:
      en: The name of the rule.
    Default: Null
    Required: false
  RuleSwitch:
    Type: Number
    Description:
      en: |-
        Specifies whether the rule is on or off. Valid values:
        * 0: off
        * 1: on
    AllowedValues:
      - 0
      - 1
    Default: Null
    Required: false
  Scope:
    Description:
      en: The scope of the rule.
    Required: false
    Default: Null
    Type: Json
    MinLength: 1
    MaxLength: 100
    AssociationProperty: List[Parameter]
    AssociationPropertyMetadata:
      Parameter:
        Description:
          en: The scope of the rule.
        Required: false
        Default: Null
        Type: Json
        AssociationPropertyMetadata:
          Parameters:
            ClusterId:
              Type: String
              Description:
                en: The cluster ID.
              Default: Null
              Required: false
            AllNamespace:
              Type: Number
              Description:
                en: |-
                  Specifies whether to include all namespaces. Valid values:
                  * 0: You can use the Namespaces property to specify the namespaces to include.
                  * 1: All namespaces are included.
              AllowedValues:
                - 0
                - 1
              Default: Null
              Required: false
            Namespaces:
              Description:
                en: The namespaces to include.
              Required: false
              Default: Null
              Type: Json
              MinLength: 1
              MaxLength: 100
              AssociationProperty: List[Parameter]
              AssociationPropertyMetadata:
                Parameter:
                  Type: String
                  Description:
                    en: The namespace to include.
                  Default: Null
                  Required: false
  WhitelistHash:
    Type: String
    Description:
      en: The whitelist hash.
    Default: Null
    Required: false
Resources:
  ExtensionResource:
    Type: ALIYUN::ThreatDetection::ContainerDefenseRule
    Properties:
      RuleType:
        Ref: RuleType
      Description:
        Ref: Description
      RuleId:
        Ref: RuleId
      Whitelist:
        Ref: Whitelist
      RuleAction:
        Ref: RuleAction
      RuleName:
        Ref: RuleName
      RuleSwitch:
        Ref: RuleSwitch
      Scope:
        Ref: Scope
      WhitelistHash:
        Ref: WhitelistHash
Outputs:
  RuleType:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleType
    Description: The rule type.
  Description:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - Description
    Description: The description of the rule.
  RuleId:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleId
    Description: The rule ID.
  Whitelist:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - Whitelist
    Description: The whitelist for the rule.
  RuleAction:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleAction
    Description: The action that is performed when the rule is matched.
  RuleName:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleName
    Description: The name of the rule.
  RuleSwitch:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - RuleSwitch
    Description: Indicates whether the rule is on or off.
  Scope:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - Scope
    Description: The scope of the rule.
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Parameters": {
    "RuleType": {
      "Type": "Number",
      "Description": {
        "en": "The rule type. Value:\n* 2: User Rules"
      },
      "AllowedValues": [
        2
      ],
      "Default": null,
      "Required": false
    },
    "Description": {
      "Type": "String",
      "Description": {
        "en": "The description of the rule."
      },
      "AssociationProperty": "TextArea",
      "Default": null,
      "Required": false
    },
    "RuleId": {
      "Type": "Number",
      "Description": {
        "en": "The rule ID."
      },
      "Default": null,
      "Required": false
    },
    "Whitelist": {
      "Description": {
        "en": "The whitelist for the rule."
      },
      "Required": false,
      "Default": null,
      "Type": "Json",
      "AssociationPropertyMetadata": {
        "Parameters": {
          "Path": {
            "Description": {
              "en": "The paths to the files that need to be added to the whitelist."
            },
            "Required": false,
            "Default": null,
            "Type": "Json",
            "AssociationProperty": "List[Parameter]",
            "AssociationPropertyMetadata": {
              "Parameter": {
                "Type": "String",
                "Description": {
                  "en": "The file path to add to the whitelist."
                },
                "Default": null,
                "Required": false
              }
            }
          },
          "Image": {
            "Description": {
              "en": "The images that need to be added to the whitelist."
            },
            "Required": false,
            "Default": null,
            "Type": "Json",
            "AssociationProperty": "List[Parameter]",
            "AssociationPropertyMetadata": {
              "Parameter": {
                "Type": "String",
                "Description": {
                  "en": "The image to add to the whitelist."
                },
                "Default": null,
                "Required": false
              }
            }
          }
        }
      }
    },
    "RuleAction": {
      "Type": "Number",
      "Description": {
        "en": "The action that is performed when the rule is matched. Valid values:\n- **1**: alert\n- **2**: block"
      },
      "AllowedValues": [
        1,
        2
      ],
      "Default": null,
      "Required": false
    },
    "RuleName": {
      "Type": "String",
      "Description": {
        "en": "The name of the rule."
      },
      "Default": null,
      "Required": false
    },
    "RuleSwitch": {
      "Type": "Number",
      "Description": {
        "en": "Specifies whether the rule is on or off. Valid values:\n* 0: off\n* 1: on"
      },
      "AllowedValues": [
        0,
        1
      ],
      "Default": null,
      "Required": false
    },
    "Scope": {
      "Description": {
        "en": "The scope of the rule."
      },
      "Required": false,
      "Default": null,
      "Type": "Json",
      "MinLength": 1,
      "MaxLength": 100,
      "AssociationProperty": "List[Parameter]",
      "AssociationPropertyMetadata": {
        "Parameter": {
          "Description": {
            "en": "The scope of the rule."
          },
          "Required": false,
          "Default": null,
          "Type": "Json",
          "AssociationPropertyMetadata": {
            "Parameters": {
              "ClusterId": {
                "Type": "String",
                "Description": {
                  "en": "The cluster ID."
                },
                "Default": null,
                "Required": false
              },
              "AllNamespace": {
                "Type": "Number",
                "Description": {
                  "en": "Specifies whether to include all namespaces. Valid values:\n* 0: You can use the Namespaces property to specify the namespaces to include.\n* 1: All namespaces are included."
                },
                "AllowedValues": [
                  0,
                  1
                ],
                "Default": null,
                "Required": false
              },
              "Namespaces": {
                "Description": {
                  "en": "The namespaces to include."
                },
                "Required": false,
                "Default": null,
                "Type": "Json",
                "MinLength": 1,
                "MaxLength": 100,
                "AssociationProperty": "List[Parameter]",
                "AssociationPropertyMetadata": {
                  "Parameter": {
                    "Type": "String",
                    "Description": {
                      "en": "The namespace to include."
                    },
                    "Default": null,
                    "Required": false
                  }
                }
              }
            }
          }
        }
      }
    },
    "WhitelistHash": {
      "Type": "String",
      "Description": {
        "en": "The whitelist hash."
      },
      "Default": null,
      "Required": false
    }
  },
  "Resources": {
    "ExtensionResource": {
      "Type": "ALIYUN::ThreatDetection::ContainerDefenseRule",
      "Properties": {
        "RuleType": {
          "Ref": "RuleType"
        },
        "Description": {
          "Ref": "Description"
        },
        "RuleId": {
          "Ref": "RuleId"
        },
        "Whitelist": {
          "Ref": "Whitelist"
        },
        "RuleAction": {
          "Ref": "RuleAction"
        },
        "RuleName": {
          "Ref": "RuleName"
        },
        "RuleSwitch": {
          "Ref": "RuleSwitch"
        },
        "Scope": {
          "Ref": "Scope"
        },
        "WhitelistHash": {
          "Ref": "WhitelistHash"
        }
      }
    }
  },
  "Outputs": {
    "RuleType": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleType"
        ]
      },
      "Description": "The rule type."
    },
    "Description": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "Description"
        ]
      },
      "Description": "The description of the rule."
    },
    "RuleId": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleId"
        ]
      },
      "Description": "The rule ID."
    },
    "Whitelist": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "Whitelist"
        ]
      },
      "Description": "The whitelist for the rule."
    },
    "RuleAction": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleAction"
        ]
      },
      "Description": "The action that is performed when the rule is matched."
    },
    "RuleName": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleName"
        ]
      },
      "Description": "The name of the rule."
    },
    "RuleSwitch": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "RuleSwitch"
        ]
      },
      "Description": "Indicates whether the rule is on or off."
    },
    "Scope": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "Scope"
        ]
      },
      "Description": "The scope of the rule."
    }
  }
}