All Products
Search
Document Center

Security Center:AddContainerDefenseRule

Last Updated:Sep 12, 2026

Creates a non-image process defense rule.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

yundun-sas:AddContainerDefenseRule

create

*ContainerDefenseRule

acs:yundun-sas:{#regionId}:{#accountId}:containerdefenserule/*

None None

Request parameters

Parameter

Type

Required

Description

Example

RuleId

integer

No

The rule ID. You do not need to specify this parameter when creating a rule.

500018

RuleAction

integer

No

The action to take when the rule is matched. Valid values:

  • 1: Alert.

  • 2: Block.

Valid values:

  • 1 :

    Alert.

  • 2 :

    Block.

1

RuleSwitch

integer

No

The rule switch. Valid values:

  • 0: Disabled.

  • 1: Enabled.

Valid values:

  • 0 :

    Disabled.

  • 1 :

    Enabled.

1

RuleName

string

No

The rule name.

auto-test-rule-lt9umq

Description

string

No

The description.

test-proc-defense

RuleType

integer

No

The rule type. Valid values:

  • 2: user rule

Important Only the value 2 is supported.

2

Whitelist

object

No

The whitelist.

Hash deprecated

array

No

The file hash.

Important This parameter is not supported.

deprecated

string

No

The hash of the whitelisted file.

hashcode

Path

array

No

The list of file paths to whitelist.

string

No

The file path to whitelist.

/test/worker.sh

Image

array

No

The list of images to whitelist.

string

No

The image to whitelist.

repo:tag

Scope

array<object>

No

The scope. This parameter is required. Specify at least one Scope entry, such as Scope.1.AllNamespace=1, which indicates that the rule applies to all namespaces. If this parameter is not specified, the API returns a 400 error.

object

No

The scope.

ClusterId

string

No

The cluster ID.

Note

You can call the DescribeGroupedContainerInstances operation to obtain this parameter.

8e2***75b

AllNamespace

integer

No

Specifies whether to include all namespaces. Valid values:

  • 0: Specifies the namespaces to include by using the Namespaces parameter.

  • 1: Includes all namespaces.

Valid values:

  • 0 :

    Specifies the namespaces to include by using the Namespaces parameter.

  • 1 :

    Includes all namespaces.

0

Namespaces

array

No

The list of included namespaces.

string

No

The included namespace.

default

Response elements

Element

Type

Description

Example

object

PlainResult

Data

integer

The returned result, which is the ID of the successfully created rule.

182

Success

boolean

Indicates whether the API call was successful. Valid values:

  • true: Successful.

  • false: Failed.

Valid values:

  • true :

    The API call was successful.

  • false :

    The API call failed.

true

Code

string

The result code. A value of 200 indicates success. Any other value indicates failure. You can use this field to determine the cause of the failure.

200

Message

string

The message returned for the API request.

There was an error with your request.

RequestId

string

The request ID, which is a unique identifier generated by Alibaba Cloud for the request. You can use this ID to troubleshoot issues.

8C376***AE74FB4

HttpStatusCode

integer

The HTTP status code of the request result.

200

Examples

Success response

JSON format

{
  "Data": 182,
  "Success": true,
  "Code": "200",
  "Message": "There was an error with your request.",
  "RequestId": "8C376***AE74FB4",
  "HttpStatusCode": 200
}

Error codes

HTTP status code

Error code

Error message

Description

500 ServerError ServerError
403 NoPermission caller has no permission You are not authorized to do this operation.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.