Creates a scan policy for detecting malicious files in OSS under the malicious file detection feature.
Operation description
Before you call this operation, call the PublicPreCheckImageScanTask operation to query the number of container images that the image scan task covers and the number of authorizations consumed. Make sure that sufficient authorizations are available for the image scan task to prevent the image scan task from being overwritten due to insufficient authorizations.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-sas:CreateOssScanConfig |
create |
*OssScanConfig
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| Enable |
integer |
No |
Specifies whether to enable the policy. Valid values:
|
1 |
| ScanDayList |
array |
No |
The scan schedule. The number indicates the day of the week. |
|
|
integer |
No |
The scan schedule. The number indicates the day of the week. |
1 |
|
| BucketNameList |
array |
No |
The list of bucket names. |
|
|
string |
No |
The bucket name. |
cccarvato-oss**** |
|
| KeySuffixList |
array |
No |
The list of file suffixes to scan. |
|
|
string |
No |
Specifies that the key of the file to scan must end with the specified suffix. |
.asp |
|
| StartTime |
string |
No |
The scan start time, in the HH:mm:ss format. |
00:00:00 |
| EndTime |
string |
No |
The scan stop time, in the HH:mm:ss format. |
01:01:00 |
| Name |
string |
No |
The policy name. |
testName |
| KeyPrefixList |
array |
No |
The file prefix list. |
|
|
string |
No |
Specifies that the key of the file to scan must start with the specified prefix. The prefix cannot start with a forward slash (/). |
/root |
|
| AllKeyPrefix |
boolean |
No |
Specifies whether to match all prefixes. If this parameter is set to true, the KeyPrefixList parameter does not take effect. |
true |
| DecompressMaxLayer |
integer |
No |
The maximum number of decompression layers when nested compressed files exist. Minimum value: 1. Maximum value: 5. When the maximum number of decompression layers is exceeded, the decompression operation stops immediately. The scanning of files that have already been decompressed is not affected. |
1 |
| DecompressMaxFileCount |
integer |
No |
The maximum number of files to decompress. Minimum value: 1. Maximum value: 1000. When the maximum number of decompressed files is exceeded, the decompression operation stops immediately. The scanning of files that have already been decompressed is not affected. |
100 |
| DecryptionList |
array |
No |
The list of decryption types. |
|
|
string |
No |
The decryption type. Valid values:
|
KMS |
|
| LastModifiedStartTime |
integer |
No |
Scans files whose last modification time is after the specified timestamp. Unit: milliseconds. |
1724301769834 |
| RealTimeIncr |
boolean |
No |
Specifies whether to enable real-time incremental scanning. If this parameter is set to true, the ScanDayList, StartTime, and EndTime parameters do not take effect. |
true |
| Source |
string |
No |
The business source. Valid values:
|
OSS |
| AutoAdd |
integer |
No |
Specifies whether OSS buckets are automatically added to this policy. Valid values:
|
0 |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can contain only ASCII characters and cannot exceed 64 characters in length. |
123e4567-e89b-12d3-a456-426655440000 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| Id |
integer |
The policy ID. |
210**** |
| RequestId |
string |
The request ID, which is a unique identifier generated by Alibaba Cloud for this request. You can use this ID to troubleshoot issues. |
5DFD6277-CC36-57F7-ACE6-F5952123**** |
Examples
Success response
JSON format
{
"Id": 0,
"RequestId": "5DFD6277-CC36-57F7-ACE6-F5952123****"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | IDEMPOTENT_PARAMETER_MISMATCH | The same ClientToken was used with different request parameters. | The same ClientToken is used for different request parameters. |
| 500 | ServerError | ServerError | |
| 403 | NoPermission | caller has no permission | You are not authorized to do this operation. |
| 409 | IDEMPOTENT_REQUEST_IN_PROGRESS | A request with the same ClientToken is still being processed. | A request using the same ClientToken is in progress. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.