All Products
Search
Document Center

Resource Orchestration Service:ALIYUN::ThreatDetection::AttackPathWhitelist

更新時間:Jul 06, 2026

The ALIYUN::ThreatDetection::AttackPathWhitelist resource creates an attack path whitelist.

Syntax

{
  "Type": "ALIYUN::ThreatDetection::AttackPathWhitelist",
  "Properties": {
    "PathType": String,
    "PathName": String,
    "WhitelistType": String,
    "WhitelistName": String,
    "AttackPathAssetList": List,
    "Remark": String
  }
}

Properties

Parameter

Type

Required

Editable

Description

Constraint

PathName

String

Yes

Yes

The name of the whitelisted path.

None

PathType

String

Yes

Yes

The type of the whitelisted path.

None

WhitelistName

String

Yes

Yes

The name of the whitelist.

None

WhitelistType

String

Yes

Yes

The type of the whitelist.

Valid values:

  • ALL_ASSET: all assets.

  • PART_ASSET: some assets.

AttackPathAssetList

List

No

Yes

The list of assets on the attack path.

You can specify from 1 to 100 assets. For more information, see AttackPathAssetList properties.

Remark

String

No

Yes

The remark for the attack path whitelist.

None

AttackPathAssetList syntax

"AttackPathAssetList": [
  {
    "AssetType": Integer,
    "InstanceId": String,
    "NodeType": String,
    "RegionId": String,
    "Vendor": Integer,
    "AssetSubType": Integer
  }
]

AttackPathAssetList properties

Parameter

Type

Required

Updatable

Description

Constraint

Vendor

Integer

Yes

Yes

The ID of the cloud service provider.

Valid value:

  • 1

AssetSubType

Integer

No

Yes

The subtype of the asset.

None

AssetType

Integer

No

Yes

The type of the asset.

None

InstanceId

String

No

Yes

The ID of the asset instance.

None

NodeType

String

No

Yes

The role of the asset in the path.

Valid values:

  • start: the start point of the path.

  • end: the end point of the path.

RegionId

String

No

Yes

The ID of the region where the asset is located.

None

Return values

Fn::GetAtt

  • PathType: The type of the whitelisted path.

  • AttackPathAssetList: The list of assets on the attack path.

  • WhitelistType: The type of the whitelist.

  • WhitelistName: The name of the whitelist.

  • PathName: The name of the whitelisted path.

  • Remark: The remark for the attack path whitelist.

  • AttackPathWhitelistId: The ID of the attack path whitelist.

Examples

ROSTemplateFormatVersion: '2015-09-01'
Parameters:
  Remark:
    Type: String
    Description: The remark for the attack path whitelist.
    Default: Null
    Required: false
  WhitelistType:
    Type: String
    Description: |-
      The type of the whitelist. Valid values:
      * ALL_ASSET: applies the whitelist to all assets.
      * PART_ASSET: applies the whitelist to specific assets.
    AllowedValues:
      - ALL_ASSET
      - PART_ASSET
    Required: true
  PathType:
    Type: String
    Description: The type of the path to be whitelisted.
    Required: true
  AttackPathAssetList:
    Description: The assets to include in the whitelist. This parameter is required only when WhitelistType is set to PART_ASSET. You can specify from 1 to 100 assets.
    Required: false
    Default: Null
    Type: Json
    MinLength: 1
    MaxLength: 100
    AssociationProperty: List[Parameters]
    AssociationPropertyMetadata:
      Parameters:
        AssetType:
          Type: Number
          Description: The type of the asset.
          Default: Null
          Required: false
        NodeType:
          Type: String
          Description: |-
            The role of the asset in the path. Valid values:
            * start: the start point of the path.
            * end: the end point of the path.
          AllowedValues:
            - start
            - end
          Default: Null
          Required: false
        InstanceId:
          Type: String
          Description: The ID of the asset instance.
          Default: Null
          Required: false
        AssetSubType:
          Type: Number
          Description: The subtype of the asset.
          Default: Null
          Required: false
        RegionId:
          Type: String
          Description: The region where the asset is located.
          Default: Null
          Required: false
        Vendor:
          Type: Number
          Description: The ID of the cloud service provider. The value must be 1, which indicates Alibaba Cloud.
          AllowedValues:
            - 1
          Required: true
  PathName:
    Type: String
    Description: The name of the path to be whitelisted.
    Required: true
  WhitelistName:
    Type: String
    Description: The name of the whitelist.
    Required: true
Resources:
  ExtensionResource:
    Type: ALIYUN::ThreatDetection::AttackPathWhitelist
    Properties:
      Remark:
        Ref: Remark
      WhitelistType:
        Ref: WhitelistType
      PathType:
        Ref: PathType
      AttackPathAssetList:
        Ref: AttackPathAssetList
      PathName:
        Ref: PathName
      WhitelistName:
        Ref: WhitelistName
Outputs:
  Remark:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - Remark
    Description: The remark for the attack path whitelist.
  WhitelistType:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - WhitelistType
    Description: The type of the whitelist.
  PathType:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - PathType
    Description: The type of the whitelisted path.
  AttackPathWhitelistId:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - AttackPathWhitelistId
    Description: The ID of the attack path whitelist.
  AttackPathAssetList:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - AttackPathAssetList
    Description: The list of assets on the attack path.
  PathName:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - PathName
    Description: The name of the whitelisted path.
  WhitelistName:
    Value:
      Fn::GetAtt:
        - ExtensionResource
        - WhitelistName
    Description: The name of the whitelist.
{
  "ROSTemplateFormatVersion": "2015-09-01",
  "Parameters": {
    "Remark": {
      "Type": "String",
      "Description": "The remark for the attack path whitelist.",
      "Default": null,
      "Required": false
    },
    "WhitelistType": {
      "Type": "String",
      "Description": "The type of the whitelist. Valid values:\n* ALL_ASSET: applies the whitelist to all assets.\n* PART_ASSET: applies the whitelist to specific assets.",
      "AllowedValues": [
        "ALL_ASSET",
        "PART_ASSET"
      ],
      "Required": true
    },
    "PathType": {
      "Type": "String",
      "Description": "The type of the path to be whitelisted.",
      "Required": true
    },
    "AttackPathAssetList": {
      "Description": "The assets to include in the whitelist. This parameter is required only when WhitelistType is set to PART_ASSET. You can specify from 1 to 100 assets.",
      "Required": false,
      "Default": null,
      "Type": "Json",
      "MinLength": 1,
      "MaxLength": 100,
      "AssociationProperty": "List[Parameters]",
      "AssociationPropertyMetadata": {
        "Parameters": {
          "AssetType": {
            "Type": "Number",
            "Description": "The type of the asset.",
            "Default": null,
            "Required": false
          },
          "NodeType": {
            "Type": "String",
            "Description": "The role of the asset in the path. Valid values:\n* start: the start point of the path.\n* end: the end point of the path.",
            "AllowedValues": [
              "start",
              "end"
            ],
            "Default": null,
            "Required": false
          },
          "InstanceId": {
            "Type": "String",
            "Description": "The ID of the asset instance.",
            "Default": null,
            "Required": false
          },
          "AssetSubType": {
            "Type": "Number",
            "Description": "The subtype of the asset.",
            "Default": null,
            "Required": false
          },
          "RegionId": {
            "Type": "String",
            "Description": "The region where the asset is located.",
            "Default": null,
            "Required": false
          },
          "Vendor": {
            "Type": "Number",
            "Description": "The ID of the cloud service provider. The value must be 1, which indicates Alibaba Cloud.",
            "AllowedValues": [
              1
            ],
            "Required": true
          }
        }
      }
    },
    "PathName": {
      "Type": "String",
      "Description": "The name of the path to be whitelisted.",
      "Required": true
    },
    "WhitelistName": {
      "Type": "String",
      "Description": "The name of the whitelist.",
      "Required": true
    }
  },
  "Resources": {
    "ExtensionResource": {
      "Type": "ALIYUN::ThreatDetection::AttackPathWhitelist",
      "Properties": {
        "Remark": {
          "Ref": "Remark"
        },
        "WhitelistType": {
          "Ref": "WhitelistType"
        },
        "PathType": {
          "Ref": "PathType"
        },
        "AttackPathAssetList": {
          "Ref": "AttackPathAssetList"
        },
        "PathName": {
          "Ref": "PathName"
        },
        "WhitelistName": {
          "Ref": "WhitelistName"
        }
      }
    }
  },
  "Outputs": {
    "Remark": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "Remark"
        ]
      },
      "Description": "The remark for the attack path whitelist."
    },
    "WhitelistType": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "WhitelistType"
        ]
      },
      "Description": "The type of the whitelist."
    },
    "PathType": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "PathType"
        ]
      },
      "Description": "The type of the whitelisted path."
    },
    "AttackPathWhitelistId": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "AttackPathWhitelistId"
        ]
      },
      "Description": "The ID of the attack path whitelist."
    },
    "AttackPathAssetList": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "AttackPathAssetList"
        ]
      },
      "Description": "The list of assets on the attack path."
    },
    "PathName": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "PathName"
        ]
      },
      "Description": "The name of the whitelisted path."
    },
    "WhitelistName": {
      "Value": {
        "Fn::GetAtt": [
          "ExtensionResource",
          "WhitelistName"
        ]
      },
      "Description": "The name of the whitelist."
    }
  }
}