Modifies the configuration of a cloud service that is connected to WAF.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
yundun-waf:ModifyCloudResource |
update |
DefenseResource
DefenseResource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| InstanceId |
string |
Yes |
The ID of the WAF instance. Note
You can call DescribeInstance to query the ID of the current WAF instance. |
waf_v3prepaid_public_cn-*** |
| ResourceManagerResourceGroupId |
string |
No |
The ID of the Alibaba Cloud resource group. |
rg-acfm***q |
| Listen |
object |
Yes |
The listening configuration. |
|
| TLSVersion |
string |
No |
The TLS version to add. This parameter is used only when HttpsPorts is not empty, which indicates that the domain name uses the HTTPS protocol. Valid values:
|
tlsv1.2 |
| EnableTLSv3 |
boolean |
No |
Specifies whether TLS 1.3 is supported. Valid values:
Note
This parameter is used only when HttpsPorts is not empty, which indicates that the domain name uses the HTTPS protocol. When TLSVersion is set to tlsv1.3, this value must be true. |
true |
| CipherSuite |
integer |
No |
The type of cipher suite to add. This parameter is used only when HttpsPorts is not empty, which indicates that the domain name uses the HTTPS protocol. Valid values:
|
1 |
| CustomCiphers |
array |
No |
The custom cipher suites. |
|
|
string |
No |
The specific custom cipher suite to add. This parameter is used only when CipherSuite is set to 99. |
ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-GCM-SHA384 |
|
ResourceProduct
deprecated
|
string |
No |
The cloud service type. Valid values:
|
clb7 |
ResourceInstanceId
deprecated
|
string |
No |
The instance ID of the resource. |
lb-*** |
Port
deprecated
|
integer |
No |
The port of the cloud service connected to WAF. |
80 |
| Protocol |
string |
Yes |
The protocol type. Valid values:
|
http |
| Certificates |
array<object> |
No |
The certificate information. |
|
|
object |
No |
The certificate information. |
||
| CertificateId |
string |
No |
The certificate ID. |
123-cn-hangzhou |
| AppliedType |
string |
No |
The certificate type for the HTTPS protocol. Valid values:
|
default |
| Http2Enabled |
boolean |
No |
Specifies whether to enable HTTP/2. This parameter is used only when HttpsPorts is not empty, which indicates that the domain name uses the HTTPS protocol. Valid values:
|
true |
| Redirect |
object |
No |
The forwarding configuration. |
|
| RequestHeaders |
array<object> |
No |
The traffic mark fields and values of the domain name, which are used to mark traffic processed by WAF. |
|
|
object |
No |
The value of this parameter is in the format of [{"k":"key","v":"value"}]. key specifies the custom request header field, and value specifies the value set for the field. Note
If the custom header field already exists in the request, the system overwrites the value of the custom field in the request with the specified traffic mark value. |
||
| Key |
string |
No |
The specified custom request header field. |
key1 |
| Value |
string |
No |
The value set for the custom request header field. |
value1 |
| XffHeaderMode |
integer |
No |
The method that WAF uses to obtain the originating IP address of the client. Valid values:
|
0 |
| XffHeaders |
array |
No |
The list of custom fields used to obtain the client IP address, in the format of ["header1","header2",……]. Note
This parameter is required only when XffHeaderMode is set to 2, which indicates that WAF reads the value of a custom header field that you specify as the client IP address. |
|
|
string |
No |
The list of custom fields used to obtain the client IP address, in the format of ["header1","header2",……]. Note
This parameter is required only when XffHeaderMode is set to 2, which indicates that WAF reads the value of a custom header field that you specify as the client IP address. |
header1 |
|
| ReadTimeout |
integer |
No |
The read timeout period. Unit: seconds. Valid values: 1 to 3600. |
1 |
| WriteTimeout |
integer |
No |
The write timeout period. Unit: seconds. Valid values: 1 to 3600. |
1 |
| Keepalive |
boolean |
No |
Specifies whether to enable persistent connections. Valid values:
|
true |
| KeepaliveRequests |
integer |
No |
The number of requests that can reuse a persistent connection. Valid values: 60 to 1000. Note
After persistent connections are enabled, this parameter specifies how many requests can reuse a persistent connection. |
1000 |
| KeepaliveTimeout |
integer |
No |
The idle timeout period for persistent connections. Valid values: 10 to 3600. Default value: 3600. Unit: seconds. Note
Specifies how long an idle persistent connection can remain open before it is released. |
15 |
| XffProto |
boolean |
No |
Specifies whether to use X-Forward-For-Proto to pass the protocol used by WAF. Valid values:
|
true |
| MaxBodySize |
integer |
No |
The maximum request body size. Valid values: 2 to 10. Default value: 2. Unit: GB. |
2 |
| RegionId |
string |
Yes |
The region where the WAF instance resides. Valid values:
|
cn-hangzhou |
| CloudResourceId |
string |
No |
The ID of the connected resource, which is automatically generated by WAF during cloud native mode connection. Note
You can call CreateCloudResource to connect a resource and then view the resource ID in the response. |
lb-***-80-clb7 |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| RequestId |
string |
The request ID. |
D7861F61-5B61-46CE-A47C-*** |
| CloudResource |
string |
The connected resource ID. |
lb-xxx-80-clb7 |
Examples
Success response
JSON format
{
"RequestId": "D7861F61-5B61-46CE-A47C-***",
"CloudResource": "lb-xxx-80-clb7"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | Waf.Pullin.CertExpired | Certificate expired, certificate ID:%s . | Certificate expired, certificate ID:%s. |
| 400 | Waf.Pullin.CertNotExist | Certificate does not exist in SSL Certificate Center, certificate type:%s, certificate ID:%s. | Certificate does not exist in SSL Certificate Center, certificate type:%s, certificate ID:%s. |
| 400 | Waf.Pullin.OnlyBeOneDefaultCert | There can be only one default certificate. | There can be only one default certificate. |
| 400 | Waf.Control.CloudProductInfoNotMartch | The value of the cloud product, port, instance, and input parameter to which the resource ID of the cloud product is connected to WAF does not match. | The value of the cloud product, port, instance, and input parameter to which the resource ID of the cloud product is connected to WAF does not match. |
| 400 | Waf.Control.CloudProductInfoEmpty | The resource Id of the cloud product accessing WAF is null or null values exist in the three input parameters of the cloud product name, port, and cloud product instance. | The resource Id of the cloud product accessing WAF is null or null values exist in the three input parameters of the cloud product name, port, and cloud product instance. |
| 400 | Waf.Control.DefenseResourceEmpty | CloudResourceId parameter is illegal. | CloudResourceId parameter is illegal |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.