akamai.AppSecEvalPenaltyBox

Scopes: Security policy

ASE_Beta.: Modifies the penalty box settings for a security policy in evaluation mode - evaluation penalty box. When the penalty box is enabled for a policy in evaluation mode, clients that trigger a WAF Deny action are placed in the “penalty box”. There, the action you select for the penalty box (either Alert or Deny) continues to apply to any requests from that client for the next 10 minutes.

Related API Endpoint: /appsec/v1/configs/{configId}/versions/{versionNumber}/security-policies/{policyId}/eval_penalty-box

Example Usage

Basic usage

using System.Collections.Generic;
using Pulumi;
using Akamai = Pulumi.Akamai;

return await Deployment.RunAsync(() => 
{
    var configuration = Akamai.GetAppSecConfiguration.Invoke(new()
    {
        Name = "Documentation",
    });

    var evalPenaltyBox = new Akamai.AppSecEvalPenaltyBox("evalPenaltyBox", new()
    {
        ConfigId = configuration.Apply(getAppSecConfigurationResult => getAppSecConfigurationResult.ConfigId),
        SecurityPolicyId = "gms1_134637",
        PenaltyBoxProtection = true,
        PenaltyBoxAction = "deny",
    });

});
package main

import (
	"github.com/pulumi/pulumi-akamai/sdk/v4/go/akamai"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		configuration, err := akamai.LookupAppSecConfiguration(ctx, &akamai.LookupAppSecConfigurationArgs{
			Name: pulumi.StringRef("Documentation"),
		}, nil)
		if err != nil {
			return err
		}
		_, err = akamai.NewAppSecEvalPenaltyBox(ctx, "evalPenaltyBox", &akamai.AppSecEvalPenaltyBoxArgs{
			ConfigId:             *pulumi.Int(configuration.ConfigId),
			SecurityPolicyId:     pulumi.String("gms1_134637"),
			PenaltyBoxProtection: pulumi.Bool(true),
			PenaltyBoxAction:     pulumi.String("deny"),
		})
		if err != nil {
			return err
		}
		return nil
	})
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.akamai.AkamaiFunctions;
import com.pulumi.akamai.inputs.GetAppSecConfigurationArgs;
import com.pulumi.akamai.AppSecEvalPenaltyBox;
import com.pulumi.akamai.AppSecEvalPenaltyBoxArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        final var configuration = AkamaiFunctions.getAppSecConfiguration(GetAppSecConfigurationArgs.builder()
            .name("Documentation")
            .build());

        var evalPenaltyBox = new AppSecEvalPenaltyBox("evalPenaltyBox", AppSecEvalPenaltyBoxArgs.builder()        
            .configId(configuration.applyValue(getAppSecConfigurationResult -> getAppSecConfigurationResult.configId()))
            .securityPolicyId("gms1_134637")
            .penaltyBoxProtection(true)
            .penaltyBoxAction("deny")
            .build());

    }
}
import pulumi
import pulumi_akamai as akamai

configuration = akamai.get_app_sec_configuration(name="Documentation")
eval_penalty_box = akamai.AppSecEvalPenaltyBox("evalPenaltyBox",
    config_id=configuration.config_id,
    security_policy_id="gms1_134637",
    penalty_box_protection=True,
    penalty_box_action="deny")
import * as pulumi from "@pulumi/pulumi";
import * as akamai from "@pulumi/akamai";

const configuration = akamai.getAppSecConfiguration({
    name: "Documentation",
});
const evalPenaltyBox = new akamai.AppSecEvalPenaltyBox("evalPenaltyBox", {
    configId: configuration.then(configuration => configuration.configId),
    securityPolicyId: "gms1_134637",
    penaltyBoxProtection: true,
    penaltyBoxAction: "deny",
});
resources:
  evalPenaltyBox:
    type: akamai:AppSecEvalPenaltyBox
    properties:
      configId: ${configuration.configId}
      securityPolicyId: gms1_134637
      penaltyBoxProtection: true
      penaltyBoxAction: deny
variables:
  configuration:
    fn::invoke:
      Function: akamai:getAppSecConfiguration
      Arguments:
        name: Documentation

Create AppSecEvalPenaltyBox Resource

new AppSecEvalPenaltyBox(name: string, args: AppSecEvalPenaltyBoxArgs, opts?: CustomResourceOptions);
@overload
def AppSecEvalPenaltyBox(resource_name: str,
                         opts: Optional[ResourceOptions] = None,
                         config_id: Optional[int] = None,
                         penalty_box_action: Optional[str] = None,
                         penalty_box_protection: Optional[bool] = None,
                         security_policy_id: Optional[str] = None)
@overload
def AppSecEvalPenaltyBox(resource_name: str,
                         args: AppSecEvalPenaltyBoxArgs,
                         opts: Optional[ResourceOptions] = None)
func NewAppSecEvalPenaltyBox(ctx *Context, name string, args AppSecEvalPenaltyBoxArgs, opts ...ResourceOption) (*AppSecEvalPenaltyBox, error)
public AppSecEvalPenaltyBox(string name, AppSecEvalPenaltyBoxArgs args, CustomResourceOptions? opts = null)
public AppSecEvalPenaltyBox(String name, AppSecEvalPenaltyBoxArgs args)
public AppSecEvalPenaltyBox(String name, AppSecEvalPenaltyBoxArgs args, CustomResourceOptions options)
type: akamai:AppSecEvalPenaltyBox
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.

name string
The unique name of the resource.
args AppSecEvalPenaltyBoxArgs
The arguments to resource properties.
opts CustomResourceOptions
Bag of options to control resource's behavior.
resource_name str
The unique name of the resource.
args AppSecEvalPenaltyBoxArgs
The arguments to resource properties.
opts ResourceOptions
Bag of options to control resource's behavior.
ctx Context
Context object for the current deployment.
name string
The unique name of the resource.
args AppSecEvalPenaltyBoxArgs
The arguments to resource properties.
opts ResourceOption
Bag of options to control resource's behavior.
name string
The unique name of the resource.
args AppSecEvalPenaltyBoxArgs
The arguments to resource properties.
opts CustomResourceOptions
Bag of options to control resource's behavior.
name String
The unique name of the resource.
args AppSecEvalPenaltyBoxArgs
The arguments to resource properties.
options CustomResourceOptions
Bag of options to control resource's behavior.

AppSecEvalPenaltyBox Resource Properties

To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

Inputs

The AppSecEvalPenaltyBox resource accepts the following input properties:

ConfigId int

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

PenaltyBoxAction string

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
PenaltyBoxProtection bool

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

SecurityPolicyId string

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

ConfigId int

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

PenaltyBoxAction string

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
PenaltyBoxProtection bool

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

SecurityPolicyId string

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

configId Integer

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penaltyBoxAction String

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penaltyBoxProtection Boolean

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

securityPolicyId String

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

configId number

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penaltyBoxAction string

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penaltyBoxProtection boolean

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

securityPolicyId string

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

config_id int

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penalty_box_action str

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penalty_box_protection bool

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

security_policy_id str

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

configId Number

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penaltyBoxAction String

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penaltyBoxProtection Boolean

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

securityPolicyId String

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

Outputs

All input properties are implicitly available as output properties. Additionally, the AppSecEvalPenaltyBox resource produces the following output properties:

Id string

The provider-assigned unique ID for this managed resource.

Id string

The provider-assigned unique ID for this managed resource.

id String

The provider-assigned unique ID for this managed resource.

id string

The provider-assigned unique ID for this managed resource.

id str

The provider-assigned unique ID for this managed resource.

id String

The provider-assigned unique ID for this managed resource.

Look up Existing AppSecEvalPenaltyBox Resource

Get an existing AppSecEvalPenaltyBox resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

public static get(name: string, id: Input<ID>, state?: AppSecEvalPenaltyBoxState, opts?: CustomResourceOptions): AppSecEvalPenaltyBox
@staticmethod
def get(resource_name: str,
        id: str,
        opts: Optional[ResourceOptions] = None,
        config_id: Optional[int] = None,
        penalty_box_action: Optional[str] = None,
        penalty_box_protection: Optional[bool] = None,
        security_policy_id: Optional[str] = None) -> AppSecEvalPenaltyBox
func GetAppSecEvalPenaltyBox(ctx *Context, name string, id IDInput, state *AppSecEvalPenaltyBoxState, opts ...ResourceOption) (*AppSecEvalPenaltyBox, error)
public static AppSecEvalPenaltyBox Get(string name, Input<string> id, AppSecEvalPenaltyBoxState? state, CustomResourceOptions? opts = null)
public static AppSecEvalPenaltyBox get(String name, Output<String> id, AppSecEvalPenaltyBoxState state, CustomResourceOptions options)
Resource lookup is not supported in YAML
name
The unique name of the resulting resource.
id
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
resource_name
The unique name of the resulting resource.
id
The unique provider ID of the resource to lookup.
name
The unique name of the resulting resource.
id
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
name
The unique name of the resulting resource.
id
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
name
The unique name of the resulting resource.
id
The unique provider ID of the resource to lookup.
state
Any extra arguments used during the lookup.
opts
A bag of options that control this resource's behavior.
The following state arguments are supported:
ConfigId int

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

PenaltyBoxAction string

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
PenaltyBoxProtection bool

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

SecurityPolicyId string

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

ConfigId int

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

PenaltyBoxAction string

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
PenaltyBoxProtection bool

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

SecurityPolicyId string

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

configId Integer

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penaltyBoxAction String

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penaltyBoxProtection Boolean

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

securityPolicyId String

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

configId number

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penaltyBoxAction string

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penaltyBoxProtection boolean

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

securityPolicyId string

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

config_id int

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penalty_box_action str

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penalty_box_protection bool

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

security_policy_id str

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

configId Number

. Unique identifier of the security configuration associated with the evaluation penalty box settings being modified.

penaltyBoxAction String

. Action taken any time evaluation penalty box protection is triggered. Allowed values are:

  • alert. Record the event.
  • deny. Block the request.
  • **deny_custom_{custom_deny_id}**. Take the action specified by the custom deny.
  • none. Take no action.
penaltyBoxProtection Boolean

. Set to true to enable evaluation penalty box protection; set to false to disable evaluation penalty box protection.

securityPolicyId String

. Unique identifier of the security policy associated with the evaluation penalty box settings being modified.

Package Details

Repository
Akamai pulumi/pulumi-akamai
License
Apache-2.0
Notes

This Pulumi package is based on the akamai Terraform Provider.