The ALIYUN::ThreatDetection::ContainerDefenseRule type creates a defense rule for runtime programs.
Syntax
{
"Type": "ALIYUN::ThreatDetection::ContainerDefenseRule",
"Properties": {
"Description": String,
"RuleSwitch": Integer,
"RuleId": Integer,
"RuleAction": Integer,
"RuleType": Integer,
"RuleName": String,
"Scope": List,
"WhitelistHash": String,
"Whitelist": Map
}
}Properties
Parameter | Type | Required | Editable | Description | Constraints |
Description | String | No | Yes | The description of the rule. | None |
RuleAction | Integer | No | Yes | The action to take when the rule is matched. | Valid values:
|
RuleId | Integer | No | No | The unique ID for the rule. | None |
RuleName | String | No | Yes | The user-defined name for the rule. | None |
RuleSwitch | Integer | No | Yes | Indicates whether the rule is enabled or disabled. | Valid values:
|
RuleType | Integer | No | Yes | The rule type. | Valid values:
|
Scope | List | No | Yes | The scope of the rule. | Length: 1 to 100. For more information, see Scope properties. |
Whitelist | Map | No | Yes | The whitelist for the rule. | For more information, see Whitelist properties. |
WhitelistHash | String | No | No | The hash of the whitelist. | None |
Scope syntax
"Scope": [
{
"Namespaces": List,
"ClusterId": String,
"AllNamespace": Integer
}
]Scope properties
Parameter | Type | Required | Editable | Description | Constraints |
AllNamespace | Integer | No | Yes | Specifies whether to include all namespaces. | Valid values:
|
ClusterId | String | No | Yes | The ID of the cluster to which the rule applies. | None |
Namespaces | List | No | Yes | The namespaces to include. | Length: 1 to 100. |
Whitelist syntax
"Whitelist": {
"Path": List,
"Image": List
}Whitelist properties
Parameter | Type | Required | Editable | Description | Constraints |
Image | List | No | Yes | The images to add to the whitelist. | None |
Path | List | No | Yes | The file paths to add to the whitelist. | None |
Outputs
Fn::GetAtt
RuleSwitch: Indicates whether the rule is on (1) or off (0).
Description: The description of the rule.
Scope: The scope of the rule.
RuleId: The unique ID for the rule.
RuleAction: The action taken when the rule is matched.
Whitelist: The whitelist for the rule.
RuleType: The rule type.
RuleName: The rule name.
Examples
ROSTemplateFormatVersion: '2015-09-01'
Parameters:
RuleType:
Type: Number
Description:
en: |-
The rule type. Value:
* 2: User Rules
AllowedValues:
- 2
Default: Null
Required: false
Description:
Type: String
Description:
en: The description of the rule.
AssociationProperty: TextArea
Default: Null
Required: false
RuleId:
Type: Number
Description:
en: The rule ID.
Default: Null
Required: false
Whitelist:
Description:
en: The whitelist for the rule.
Required: false
Default: Null
Type: Json
AssociationPropertyMetadata:
Parameters:
Path:
Description:
en: The paths to the files that need to be added to the whitelist.
Required: false
Default: Null
Type: Json
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Type: String
Description:
en: The file path to add to the whitelist.
Default: Null
Required: false
Image:
Description:
en: The images that need to be added to the whitelist.
Required: false
Default: Null
Type: Json
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Type: String
Description:
en: The image to add to the whitelist.
Default: Null
Required: false
RuleAction:
Type: Number
Description:
en: |-
The action that is performed when the rule is matched. Valid values:
- **1**: alert
- **2**: block
AllowedValues:
- 1
- 2
Default: Null
Required: false
RuleName:
Type: String
Description:
en: The name of the rule.
Default: Null
Required: false
RuleSwitch:
Type: Number
Description:
en: |-
Specifies whether the rule is on or off. Valid values:
* 0: off
* 1: on
AllowedValues:
- 0
- 1
Default: Null
Required: false
Scope:
Description:
en: The scope of the rule.
Required: false
Default: Null
Type: Json
MinLength: 1
MaxLength: 100
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Description:
en: The scope of the rule.
Required: false
Default: Null
Type: Json
AssociationPropertyMetadata:
Parameters:
ClusterId:
Type: String
Description:
en: The cluster ID.
Default: Null
Required: false
AllNamespace:
Type: Number
Description:
en: |-
Specifies whether to include all namespaces. Valid values:
* 0: You can use the Namespaces property to specify the namespaces to include.
* 1: All namespaces are included.
AllowedValues:
- 0
- 1
Default: Null
Required: false
Namespaces:
Description:
en: The namespaces to include.
Required: false
Default: Null
Type: Json
MinLength: 1
MaxLength: 100
AssociationProperty: List[Parameter]
AssociationPropertyMetadata:
Parameter:
Type: String
Description:
en: The namespace to include.
Default: Null
Required: false
WhitelistHash:
Type: String
Description:
en: The whitelist hash.
Default: Null
Required: false
Resources:
ExtensionResource:
Type: ALIYUN::ThreatDetection::ContainerDefenseRule
Properties:
RuleType:
Ref: RuleType
Description:
Ref: Description
RuleId:
Ref: RuleId
Whitelist:
Ref: Whitelist
RuleAction:
Ref: RuleAction
RuleName:
Ref: RuleName
RuleSwitch:
Ref: RuleSwitch
Scope:
Ref: Scope
WhitelistHash:
Ref: WhitelistHash
Outputs:
RuleType:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleType
Description: The rule type.
Description:
Value:
Fn::GetAtt:
- ExtensionResource
- Description
Description: The description of the rule.
RuleId:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleId
Description: The rule ID.
Whitelist:
Value:
Fn::GetAtt:
- ExtensionResource
- Whitelist
Description: The whitelist for the rule.
RuleAction:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleAction
Description: The action that is performed when the rule is matched.
RuleName:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleName
Description: The name of the rule.
RuleSwitch:
Value:
Fn::GetAtt:
- ExtensionResource
- RuleSwitch
Description: Indicates whether the rule is on or off.
Scope:
Value:
Fn::GetAtt:
- ExtensionResource
- Scope
Description: The scope of the rule.
{
"ROSTemplateFormatVersion": "2015-09-01",
"Parameters": {
"RuleType": {
"Type": "Number",
"Description": {
"en": "The rule type. Value:\n* 2: User Rules"
},
"AllowedValues": [
2
],
"Default": null,
"Required": false
},
"Description": {
"Type": "String",
"Description": {
"en": "The description of the rule."
},
"AssociationProperty": "TextArea",
"Default": null,
"Required": false
},
"RuleId": {
"Type": "Number",
"Description": {
"en": "The rule ID."
},
"Default": null,
"Required": false
},
"Whitelist": {
"Description": {
"en": "The whitelist for the rule."
},
"Required": false,
"Default": null,
"Type": "Json",
"AssociationPropertyMetadata": {
"Parameters": {
"Path": {
"Description": {
"en": "The paths to the files that need to be added to the whitelist."
},
"Required": false,
"Default": null,
"Type": "Json",
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Type": "String",
"Description": {
"en": "The file path to add to the whitelist."
},
"Default": null,
"Required": false
}
}
},
"Image": {
"Description": {
"en": "The images that need to be added to the whitelist."
},
"Required": false,
"Default": null,
"Type": "Json",
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Type": "String",
"Description": {
"en": "The image to add to the whitelist."
},
"Default": null,
"Required": false
}
}
}
}
}
},
"RuleAction": {
"Type": "Number",
"Description": {
"en": "The action that is performed when the rule is matched. Valid values:\n- **1**: alert\n- **2**: block"
},
"AllowedValues": [
1,
2
],
"Default": null,
"Required": false
},
"RuleName": {
"Type": "String",
"Description": {
"en": "The name of the rule."
},
"Default": null,
"Required": false
},
"RuleSwitch": {
"Type": "Number",
"Description": {
"en": "Specifies whether the rule is on or off. Valid values:\n* 0: off\n* 1: on"
},
"AllowedValues": [
0,
1
],
"Default": null,
"Required": false
},
"Scope": {
"Description": {
"en": "The scope of the rule."
},
"Required": false,
"Default": null,
"Type": "Json",
"MinLength": 1,
"MaxLength": 100,
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Description": {
"en": "The scope of the rule."
},
"Required": false,
"Default": null,
"Type": "Json",
"AssociationPropertyMetadata": {
"Parameters": {
"ClusterId": {
"Type": "String",
"Description": {
"en": "The cluster ID."
},
"Default": null,
"Required": false
},
"AllNamespace": {
"Type": "Number",
"Description": {
"en": "Specifies whether to include all namespaces. Valid values:\n* 0: You can use the Namespaces property to specify the namespaces to include.\n* 1: All namespaces are included."
},
"AllowedValues": [
0,
1
],
"Default": null,
"Required": false
},
"Namespaces": {
"Description": {
"en": "The namespaces to include."
},
"Required": false,
"Default": null,
"Type": "Json",
"MinLength": 1,
"MaxLength": 100,
"AssociationProperty": "List[Parameter]",
"AssociationPropertyMetadata": {
"Parameter": {
"Type": "String",
"Description": {
"en": "The namespace to include."
},
"Default": null,
"Required": false
}
}
}
}
}
}
}
},
"WhitelistHash": {
"Type": "String",
"Description": {
"en": "The whitelist hash."
},
"Default": null,
"Required": false
}
},
"Resources": {
"ExtensionResource": {
"Type": "ALIYUN::ThreatDetection::ContainerDefenseRule",
"Properties": {
"RuleType": {
"Ref": "RuleType"
},
"Description": {
"Ref": "Description"
},
"RuleId": {
"Ref": "RuleId"
},
"Whitelist": {
"Ref": "Whitelist"
},
"RuleAction": {
"Ref": "RuleAction"
},
"RuleName": {
"Ref": "RuleName"
},
"RuleSwitch": {
"Ref": "RuleSwitch"
},
"Scope": {
"Ref": "Scope"
},
"WhitelistHash": {
"Ref": "WhitelistHash"
}
}
}
},
"Outputs": {
"RuleType": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleType"
]
},
"Description": "The rule type."
},
"Description": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"Description"
]
},
"Description": "The description of the rule."
},
"RuleId": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleId"
]
},
"Description": "The rule ID."
},
"Whitelist": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"Whitelist"
]
},
"Description": "The whitelist for the rule."
},
"RuleAction": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleAction"
]
},
"Description": "The action that is performed when the rule is matched."
},
"RuleName": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleName"
]
},
"Description": "The name of the rule."
},
"RuleSwitch": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"RuleSwitch"
]
},
"Description": "Indicates whether the rule is on or off."
},
"Scope": {
"Value": {
"Fn::GetAtt": [
"ExtensionResource",
"Scope"
]
},
"Description": "The scope of the rule."
}
}
}