published on Thursday, Sep 17, 2026 by Checkly
published on Thursday, Sep 17, 2026 by Checkly
SSL monitors check the TLS certificate of a host and alert before it expires or violates a security baseline.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as checkly from "@checkly/pulumi";
// Basic SSL/TLS certificate monitor
const example_ssl_monitor = new checkly.SslMonitor("example-ssl-monitor", {
name: "Example SSL monitor",
activated: true,
shouldFail: false,
frequency: 60,
useGlobalAlertSettings: true,
locations: ["us-west-1"],
request: {
hostname: "api.checklyhq.com",
port: 443,
alertDaysBeforeExpiry: 30,
},
});
// A more complex example with response-time thresholds, a custom security
// baseline and certificate assertions
const example_ssl_monitor_2 = new checkly.SslMonitor("example-ssl-monitor-2", {
name: "Example SSL monitor 2",
activated: true,
shouldFail: false,
frequency: 60,
degradedResponseTime: 3000,
maxResponseTime: 10000,
locations: [
"us-west-1",
"eu-central-1",
],
alertSettings: {
escalationType: "RUN_BASED",
runBasedEscalations: [{
failedRunThreshold: 1,
}],
reminders: [{
amount: 1,
}],
},
request: {
hostname: "api.checklyhq.com",
port: 443,
serverName: "api.checklyhq.com",
ipFamily: "IPv4",
skipChainValidation: false,
handshakeTimeoutMs: 10000,
alertDaysBeforeExpiry: 20,
securityBaseline: {
minTlsVersion: {
value: "TLS1.2",
severity: "fail",
},
minKeySizeBits: {
value: 2048,
severity: "fail",
},
},
clientCertificate: {
mode: "account_default",
},
assertions: [
{
source: "CERTIFICATE",
property: "daysUntilExpiry",
comparison: "GREATER_THAN",
target: "14",
},
{
source: "CONNECTION",
property: "hostnameVerified",
comparison: "EQUALS",
target: "true",
},
],
},
});
import pulumi
import pulumi_checkly as checkly
# Basic SSL/TLS certificate monitor
example_ssl_monitor = checkly.SslMonitor("example-ssl-monitor",
name="Example SSL monitor",
activated=True,
should_fail=False,
frequency=60,
use_global_alert_settings=True,
locations=["us-west-1"],
request={
"hostname": "api.checklyhq.com",
"port": 443,
"alert_days_before_expiry": 30,
})
# A more complex example with response-time thresholds, a custom security
# baseline and certificate assertions
example_ssl_monitor_2 = checkly.SslMonitor("example-ssl-monitor-2",
name="Example SSL monitor 2",
activated=True,
should_fail=False,
frequency=60,
degraded_response_time=3000,
max_response_time=10000,
locations=[
"us-west-1",
"eu-central-1",
],
alert_settings={
"escalation_type": "RUN_BASED",
"run_based_escalations": [{
"failed_run_threshold": 1,
}],
"reminders": [{
"amount": 1,
}],
},
request={
"hostname": "api.checklyhq.com",
"port": 443,
"server_name": "api.checklyhq.com",
"ip_family": "IPv4",
"skip_chain_validation": False,
"handshake_timeout_ms": 10000,
"alert_days_before_expiry": 20,
"security_baseline": {
"min_tls_version": {
"value": "TLS1.2",
"severity": "fail",
},
"min_key_size_bits": {
"value": 2048,
"severity": "fail",
},
},
"client_certificate": {
"mode": "account_default",
},
"assertions": [
{
"source": "CERTIFICATE",
"property": "daysUntilExpiry",
"comparison": "GREATER_THAN",
"target": "14",
},
{
"source": "CONNECTION",
"property": "hostnameVerified",
"comparison": "EQUALS",
"target": "true",
},
],
})
package main
import (
"github.com/checkly/pulumi-checkly/sdk/v2/go/checkly"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
// Basic SSL/TLS certificate monitor
_, err := checkly.NewSslMonitor(ctx, "example-ssl-monitor", &checkly.SslMonitorArgs{
Name: pulumi.String("Example SSL monitor"),
Activated: pulumi.Bool(true),
ShouldFail: pulumi.Bool(false),
Frequency: pulumi.Int(60),
UseGlobalAlertSettings: pulumi.Bool(true),
Locations: pulumi.StringArray{
pulumi.String("us-west-1"),
},
Request: &checkly.SslMonitorRequestArgs{
Hostname: pulumi.String("api.checklyhq.com"),
Port: pulumi.Int(443),
AlertDaysBeforeExpiry: pulumi.Int(30),
},
})
if err != nil {
return err
}
// A more complex example with response-time thresholds, a custom security
// baseline and certificate assertions
_, err = checkly.NewSslMonitor(ctx, "example-ssl-monitor-2", &checkly.SslMonitorArgs{
Name: pulumi.String("Example SSL monitor 2"),
Activated: pulumi.Bool(true),
ShouldFail: pulumi.Bool(false),
Frequency: pulumi.Int(60),
DegradedResponseTime: pulumi.Int(3000),
MaxResponseTime: pulumi.Int(10000),
Locations: pulumi.StringArray{
pulumi.String("us-west-1"),
pulumi.String("eu-central-1"),
},
AlertSettings: &checkly.SslMonitorAlertSettingsArgs{
EscalationType: pulumi.String("RUN_BASED"),
RunBasedEscalations: checkly.SslMonitorAlertSettingsRunBasedEscalationArray{
&checkly.SslMonitorAlertSettingsRunBasedEscalationArgs{
FailedRunThreshold: pulumi.Int(1),
},
},
Reminders: checkly.SslMonitorAlertSettingsReminderArray{
&checkly.SslMonitorAlertSettingsReminderArgs{
Amount: pulumi.Int(1),
},
},
},
Request: &checkly.SslMonitorRequestArgs{
Hostname: pulumi.String("api.checklyhq.com"),
Port: pulumi.Int(443),
ServerName: pulumi.String("api.checklyhq.com"),
IpFamily: pulumi.String("IPv4"),
SkipChainValidation: pulumi.Bool(false),
HandshakeTimeoutMs: pulumi.Int(10000),
AlertDaysBeforeExpiry: pulumi.Int(20),
SecurityBaseline: &checkly.SslMonitorRequestSecurityBaselineArgs{
MinTlsVersion: &checkly.SslMonitorRequestSecurityBaselineMinTlsVersionArgs{
Value: pulumi.String("TLS1.2"),
Severity: pulumi.String("fail"),
},
MinKeySizeBits: &checkly.SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs{
Value: pulumi.Int(2048),
Severity: pulumi.String("fail"),
},
},
ClientCertificate: &checkly.SslMonitorRequestClientCertificateArgs{
Mode: pulumi.String("account_default"),
},
Assertions: checkly.SslMonitorRequestAssertionArray{
&checkly.SslMonitorRequestAssertionArgs{
Source: pulumi.String("CERTIFICATE"),
Property: pulumi.String("daysUntilExpiry"),
Comparison: pulumi.String("GREATER_THAN"),
Target: pulumi.String("14"),
},
&checkly.SslMonitorRequestAssertionArgs{
Source: pulumi.String("CONNECTION"),
Property: pulumi.String("hostnameVerified"),
Comparison: pulumi.String("EQUALS"),
Target: pulumi.String("true"),
},
},
},
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Checkly = Pulumi.Checkly;
return await Deployment.RunAsync(() =>
{
// Basic SSL/TLS certificate monitor
var example_ssl_monitor = new Checkly.SslMonitor("example-ssl-monitor", new()
{
Name = "Example SSL monitor",
Activated = true,
ShouldFail = false,
Frequency = 60,
UseGlobalAlertSettings = true,
Locations = new[]
{
"us-west-1",
},
Request = new Checkly.Inputs.SslMonitorRequestArgs
{
Hostname = "api.checklyhq.com",
Port = 443,
AlertDaysBeforeExpiry = 30,
},
});
// A more complex example with response-time thresholds, a custom security
// baseline and certificate assertions
var example_ssl_monitor_2 = new Checkly.SslMonitor("example-ssl-monitor-2", new()
{
Name = "Example SSL monitor 2",
Activated = true,
ShouldFail = false,
Frequency = 60,
DegradedResponseTime = 3000,
MaxResponseTime = 10000,
Locations = new[]
{
"us-west-1",
"eu-central-1",
},
AlertSettings = new Checkly.Inputs.SslMonitorAlertSettingsArgs
{
EscalationType = "RUN_BASED",
RunBasedEscalations = new[]
{
new Checkly.Inputs.SslMonitorAlertSettingsRunBasedEscalationArgs
{
FailedRunThreshold = 1,
},
},
Reminders = new[]
{
new Checkly.Inputs.SslMonitorAlertSettingsReminderArgs
{
Amount = 1,
},
},
},
Request = new Checkly.Inputs.SslMonitorRequestArgs
{
Hostname = "api.checklyhq.com",
Port = 443,
ServerName = "api.checklyhq.com",
IpFamily = "IPv4",
SkipChainValidation = false,
HandshakeTimeoutMs = 10000,
AlertDaysBeforeExpiry = 20,
SecurityBaseline = new Checkly.Inputs.SslMonitorRequestSecurityBaselineArgs
{
MinTlsVersion = new Checkly.Inputs.SslMonitorRequestSecurityBaselineMinTlsVersionArgs
{
Value = "TLS1.2",
Severity = "fail",
},
MinKeySizeBits = new Checkly.Inputs.SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs
{
Value = 2048,
Severity = "fail",
},
},
ClientCertificate = new Checkly.Inputs.SslMonitorRequestClientCertificateArgs
{
Mode = "account_default",
},
Assertions = new[]
{
new Checkly.Inputs.SslMonitorRequestAssertionArgs
{
Source = "CERTIFICATE",
Property = "daysUntilExpiry",
Comparison = "GREATER_THAN",
Target = "14",
},
new Checkly.Inputs.SslMonitorRequestAssertionArgs
{
Source = "CONNECTION",
Property = "hostnameVerified",
Comparison = "EQUALS",
Target = "true",
},
},
},
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.checkly.SslMonitor;
import com.pulumi.checkly.SslMonitorArgs;
import com.pulumi.checkly.inputs.SslMonitorRequestArgs;
import com.pulumi.checkly.inputs.SslMonitorAlertSettingsArgs;
import com.pulumi.checkly.inputs.SslMonitorRequestSecurityBaselineArgs;
import com.pulumi.checkly.inputs.SslMonitorRequestSecurityBaselineMinTlsVersionArgs;
import com.pulumi.checkly.inputs.SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs;
import com.pulumi.checkly.inputs.SslMonitorRequestClientCertificateArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
// Basic SSL/TLS certificate monitor
var example_ssl_monitor = new SslMonitor("example-ssl-monitor", SslMonitorArgs.builder()
.name("Example SSL monitor")
.activated(true)
.shouldFail(false)
.frequency(60)
.useGlobalAlertSettings(true)
.locations("us-west-1")
.request(SslMonitorRequestArgs.builder()
.hostname("api.checklyhq.com")
.port(443)
.alertDaysBeforeExpiry(30)
.build())
.build());
// A more complex example with response-time thresholds, a custom security
// baseline and certificate assertions
var example_ssl_monitor_2 = new SslMonitor("example-ssl-monitor-2", SslMonitorArgs.builder()
.name("Example SSL monitor 2")
.activated(true)
.shouldFail(false)
.frequency(60)
.degradedResponseTime(3000)
.maxResponseTime(10000)
.locations(
"us-west-1",
"eu-central-1")
.alertSettings(SslMonitorAlertSettingsArgs.builder()
.escalationType("RUN_BASED")
.runBasedEscalations(SslMonitorAlertSettingsRunBasedEscalationArgs.builder()
.failedRunThreshold(1)
.build())
.reminders(SslMonitorAlertSettingsReminderArgs.builder()
.amount(1)
.build())
.build())
.request(SslMonitorRequestArgs.builder()
.hostname("api.checklyhq.com")
.port(443)
.serverName("api.checklyhq.com")
.ipFamily("IPv4")
.skipChainValidation(false)
.handshakeTimeoutMs(10000)
.alertDaysBeforeExpiry(20)
.securityBaseline(SslMonitorRequestSecurityBaselineArgs.builder()
.minTlsVersion(SslMonitorRequestSecurityBaselineMinTlsVersionArgs.builder()
.value("TLS1.2")
.severity("fail")
.build())
.minKeySizeBits(SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs.builder()
.value(2048)
.severity("fail")
.build())
.build())
.clientCertificate(SslMonitorRequestClientCertificateArgs.builder()
.mode("account_default")
.build())
.assertions(
SslMonitorRequestAssertionArgs.builder()
.source("CERTIFICATE")
.property("daysUntilExpiry")
.comparison("GREATER_THAN")
.target("14")
.build(),
SslMonitorRequestAssertionArgs.builder()
.source("CONNECTION")
.property("hostnameVerified")
.comparison("EQUALS")
.target("true")
.build())
.build())
.build());
}
}
resources:
# Basic SSL/TLS certificate monitor
example-ssl-monitor:
type: checkly:SslMonitor
properties:
name: Example SSL monitor
activated: true
shouldFail: false
frequency: 60
useGlobalAlertSettings: true
locations:
- us-west-1
request:
hostname: api.checklyhq.com
port: 443
alertDaysBeforeExpiry: 30
# A more complex example with response-time thresholds, a custom security
# baseline and certificate assertions
example-ssl-monitor-2:
type: checkly:SslMonitor
properties:
name: Example SSL monitor 2
activated: true
shouldFail: false
frequency: 60
degradedResponseTime: 3000
maxResponseTime: 10000
locations:
- us-west-1
- eu-central-1
alertSettings:
escalationType: RUN_BASED
runBasedEscalations:
- failedRunThreshold: 1
reminders:
- amount: 1
request:
hostname: api.checklyhq.com
port: 443
serverName: api.checklyhq.com
ipFamily: IPv4
skipChainValidation: false
handshakeTimeoutMs: 10000
alertDaysBeforeExpiry: 20
securityBaseline:
minTlsVersion:
value: TLS1.2
severity: fail
minKeySizeBits:
value: 2048
severity: fail
clientCertificate:
mode: account_default
assertions:
- source: CERTIFICATE
property: daysUntilExpiry
comparison: GREATER_THAN
target: '14'
- source: CONNECTION
property: hostnameVerified
comparison: EQUALS
target: 'true'
Example coming soon!
Assertion Reference
Each assertion block has the shape { source, property, comparison, target }. SSL assertions use a property-scoped grammar: for the CERTIFICATE and CONNECTION sources, property selects the fact being asserted, and that property determines which comparisons are allowed. These rules are enforced by the Checkly API at apply time.
Source CERTIFICATE
property is required and must be one of the following.
property | Value type | Allowed comparison values | Notes |
|---|---|---|---|
daysUntilExpiry | number | EQUALS, NOT_EQUALS, GREATER_THAN, LESS_THAN | Days until the certificate expires. |
keySizeBits | number | EQUALS, NOT_EQUALS, GREATER_THAN, LESS_THAN | Public key size in bits. |
subjectCN | string | EQUALS, NOT_EQUALS, CONTAINS, NOT_CONTAINS | Subject common name. |
issuerCN | string | EQUALS, NOT_EQUALS, CONTAINS, NOT_CONTAINS | Issuer common name. |
serialNumber | string | EQUALS, NOT_EQUALS | |
fingerprintSha256 | string | EQUALS, NOT_EQUALS | |
issuerFingerprintSha256 | string | EQUALS, NOT_EQUALS | |
keyAlgorithm | string | EQUALS, NOT_EQUALS | |
signatureAlgorithm | string | EQUALS, NOT_EQUALS | e.g. SHA256-RSA, ECDSA-SHA256, Ed25519. |
sans | list of strings | CONTAINS, NOT_CONTAINS | Subject alternative names. |
selfSigned | boolean | EQUALS only | target is "true" or "false". |
isCA | boolean | EQUALS only | target is "true" or "false". |
Source CONNECTION
property is required and must be one of the following.
property | Value type | Allowed comparison values | Notes |
|---|---|---|---|
tlsVersion | string (ordered) | EQUALS, NOT_EQUALS, GREATER_THAN, LESS_THAN | TLS versions compare in protocol order, e.g. GREATER_THAN TLSv1.2 matches TLS 1.3. |
cipherSuite | string | EQUALS, NOT_EQUALS, CONTAINS, NOT_CONTAINS | IANA cipher suite name. |
hostnameVerified | boolean | EQUALS only | target is "true" or "false". |
chainTrusted | boolean | EQUALS only | target is "true" or "false". |
ocspStapled | boolean | EQUALS only | target is "true" or "false". |
ocspStatus | string | EQUALS, NOT_EQUALS | |
resolvedIp | string | EQUALS, NOT_EQUALS, CONTAINS, NOT_CONTAINS |
Other sources
source | property | Allowed comparison values | target |
|---|---|---|---|
RESPONSE_TIME | Must be empty. | EQUALS, NOT_EQUALS, GREATER_THAN, LESS_THAN | Handshake time in milliseconds, ≥ 0. |
JSON_RESPONSE | Required. A JSONPath expression over the check result (e.g. $.certificate.keySizeBits). | EQUALS, NOT_EQUALS, IS_EMPTY, NOT_EMPTY, GREATER_THAN, LESS_THAN, CONTAINS, NOT_CONTAINS, IS_NULL, NOT_NULL | Free-form string. |
TEXT_RESPONSE | Optional. A regular expression applied to the serialized response; empty matches the whole response. | EQUALS, NOT_EQUALS, IS_EMPTY, NOT_EMPTY, CONTAINS, NOT_CONTAINS, GREATER_THAN, LESS_THAN | Free-form string. |
Create SslMonitor Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new SslMonitor(name: string, args: SslMonitorArgs, opts?: CustomResourceOptions);@overload
def SslMonitor(resource_name: str,
args: SslMonitorArgs,
opts: Optional[ResourceOptions] = None)
@overload
def SslMonitor(resource_name: str,
opts: Optional[ResourceOptions] = None,
frequency: Optional[int] = None,
request: Optional[SslMonitorRequestArgs] = None,
activated: Optional[bool] = None,
max_response_time: Optional[int] = None,
name: Optional[str] = None,
degraded_response_time: Optional[int] = None,
frequency_offset: Optional[int] = None,
group_id: Optional[int] = None,
group_order: Optional[int] = None,
locations: Optional[Sequence[str]] = None,
alert_settings: Optional[SslMonitorAlertSettingsArgs] = None,
muted: Optional[bool] = None,
description: Optional[str] = None,
private_locations: Optional[Sequence[str]] = None,
alert_channel_subscriptions: Optional[Sequence[SslMonitorAlertChannelSubscriptionArgs]] = None,
retry_strategy: Optional[SslMonitorRetryStrategyArgs] = None,
run_parallel: Optional[bool] = None,
runtime_id: Optional[str] = None,
should_fail: Optional[bool] = None,
tags: Optional[Sequence[str]] = None,
trigger_incident: Optional[SslMonitorTriggerIncidentArgs] = None,
use_global_alert_settings: Optional[bool] = None)func NewSslMonitor(ctx *Context, name string, args SslMonitorArgs, opts ...ResourceOption) (*SslMonitor, error)public SslMonitor(string name, SslMonitorArgs args, CustomResourceOptions? opts = null)
public SslMonitor(String name, SslMonitorArgs args)
public SslMonitor(String name, SslMonitorArgs args, CustomResourceOptions options)
type: checkly:SslMonitor
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "checkly_ssl_monitor" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args SslMonitorArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args SslMonitorArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args SslMonitorArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args SslMonitorArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args SslMonitorArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var sslMonitorResource = new Checkly.SslMonitor("sslMonitorResource", new()
{
Frequency = 0,
Request = new Checkly.Inputs.SslMonitorRequestArgs
{
Hostname = "string",
AlertDaysBeforeExpiry = 0,
Assertions = new[]
{
new Checkly.Inputs.SslMonitorRequestAssertionArgs
{
Comparison = "string",
Source = "string",
Property = "string",
Target = "string",
},
},
ClientCertificate = new Checkly.Inputs.SslMonitorRequestClientCertificateArgs
{
ClientCertificateId = "string",
Mode = "string",
},
HandshakeTimeoutMs = 0,
IpFamily = "string",
Port = 0,
SecurityBaseline = new Checkly.Inputs.SslMonitorRequestSecurityBaselineArgs
{
Enabled = false,
KnownBadCa = new Checkly.Inputs.SslMonitorRequestSecurityBaselineKnownBadCaArgs
{
Severity = "string",
},
MinKeySizeBits = new Checkly.Inputs.SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs
{
Severity = "string",
Value = 0,
},
MinTlsVersion = new Checkly.Inputs.SslMonitorRequestSecurityBaselineMinTlsVersionArgs
{
Severity = "string",
Value = "string",
},
OcspMustStapleRespected = new Checkly.Inputs.SslMonitorRequestSecurityBaselineOcspMustStapleRespectedArgs
{
Severity = "string",
},
RecommendedKeySizeBits = new Checkly.Inputs.SslMonitorRequestSecurityBaselineRecommendedKeySizeBitsArgs
{
Severity = "string",
Value = 0,
},
RecommendedTlsVersion = new Checkly.Inputs.SslMonitorRequestSecurityBaselineRecommendedTlsVersionArgs
{
Severity = "string",
Value = "string",
},
SctPresent = new Checkly.Inputs.SslMonitorRequestSecurityBaselineSctPresentArgs
{
Severity = "string",
},
WeakCipherSuite = new Checkly.Inputs.SslMonitorRequestSecurityBaselineWeakCipherSuiteArgs
{
Severity = "string",
},
WeakSignatureAlgorithm = new Checkly.Inputs.SslMonitorRequestSecurityBaselineWeakSignatureAlgorithmArgs
{
Severity = "string",
},
},
ServerName = "string",
SkipChainValidation = false,
},
Activated = false,
MaxResponseTime = 0,
Name = "string",
DegradedResponseTime = 0,
FrequencyOffset = 0,
GroupId = 0,
GroupOrder = 0,
Locations = new[]
{
"string",
},
AlertSettings = new Checkly.Inputs.SslMonitorAlertSettingsArgs
{
EscalationType = "string",
ParallelRunFailureThresholds = new[]
{
new Checkly.Inputs.SslMonitorAlertSettingsParallelRunFailureThresholdArgs
{
Enabled = false,
Percentage = 0,
},
},
Reminders = new[]
{
new Checkly.Inputs.SslMonitorAlertSettingsReminderArgs
{
Amount = 0,
Interval = 0,
},
},
RunBasedEscalations = new[]
{
new Checkly.Inputs.SslMonitorAlertSettingsRunBasedEscalationArgs
{
FailedRunThreshold = 0,
},
},
TimeBasedEscalations = new[]
{
new Checkly.Inputs.SslMonitorAlertSettingsTimeBasedEscalationArgs
{
MinutesFailingThreshold = 0,
},
},
},
Muted = false,
Description = "string",
PrivateLocations = new[]
{
"string",
},
AlertChannelSubscriptions = new[]
{
new Checkly.Inputs.SslMonitorAlertChannelSubscriptionArgs
{
Activated = false,
ChannelId = 0,
},
},
RetryStrategy = new Checkly.Inputs.SslMonitorRetryStrategyArgs
{
Type = "string",
BaseBackoffSeconds = 0,
MaxDurationSeconds = 0,
MaxRetries = 0,
OnlyOn = null,
SameRegion = false,
},
RunParallel = false,
RuntimeId = "string",
ShouldFail = false,
Tags = new[]
{
"string",
},
TriggerIncident = new Checkly.Inputs.SslMonitorTriggerIncidentArgs
{
Description = "string",
Name = "string",
NotifySubscribers = false,
ServiceId = "string",
Severity = "string",
},
UseGlobalAlertSettings = false,
});
example, err := checkly.NewSslMonitor(ctx, "sslMonitorResource", &checkly.SslMonitorArgs{
Frequency: pulumi.Int(0),
Request: &checkly.SslMonitorRequestArgs{
Hostname: pulumi.String("string"),
AlertDaysBeforeExpiry: pulumi.Int(0),
Assertions: checkly.SslMonitorRequestAssertionArray{
&checkly.SslMonitorRequestAssertionArgs{
Comparison: pulumi.String("string"),
Source: pulumi.String("string"),
Property: pulumi.String("string"),
Target: pulumi.String("string"),
},
},
ClientCertificate: &checkly.SslMonitorRequestClientCertificateArgs{
ClientCertificateId: pulumi.String("string"),
Mode: pulumi.String("string"),
},
HandshakeTimeoutMs: pulumi.Int(0),
IpFamily: pulumi.String("string"),
Port: pulumi.Int(0),
SecurityBaseline: &checkly.SslMonitorRequestSecurityBaselineArgs{
Enabled: pulumi.Bool(false),
KnownBadCa: &checkly.SslMonitorRequestSecurityBaselineKnownBadCaArgs{
Severity: pulumi.String("string"),
},
MinKeySizeBits: &checkly.SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs{
Severity: pulumi.String("string"),
Value: pulumi.Int(0),
},
MinTlsVersion: &checkly.SslMonitorRequestSecurityBaselineMinTlsVersionArgs{
Severity: pulumi.String("string"),
Value: pulumi.String("string"),
},
OcspMustStapleRespected: &checkly.SslMonitorRequestSecurityBaselineOcspMustStapleRespectedArgs{
Severity: pulumi.String("string"),
},
RecommendedKeySizeBits: &checkly.SslMonitorRequestSecurityBaselineRecommendedKeySizeBitsArgs{
Severity: pulumi.String("string"),
Value: pulumi.Int(0),
},
RecommendedTlsVersion: &checkly.SslMonitorRequestSecurityBaselineRecommendedTlsVersionArgs{
Severity: pulumi.String("string"),
Value: pulumi.String("string"),
},
SctPresent: &checkly.SslMonitorRequestSecurityBaselineSctPresentArgs{
Severity: pulumi.String("string"),
},
WeakCipherSuite: &checkly.SslMonitorRequestSecurityBaselineWeakCipherSuiteArgs{
Severity: pulumi.String("string"),
},
WeakSignatureAlgorithm: &checkly.SslMonitorRequestSecurityBaselineWeakSignatureAlgorithmArgs{
Severity: pulumi.String("string"),
},
},
ServerName: pulumi.String("string"),
SkipChainValidation: pulumi.Bool(false),
},
Activated: pulumi.Bool(false),
MaxResponseTime: pulumi.Int(0),
Name: pulumi.String("string"),
DegradedResponseTime: pulumi.Int(0),
FrequencyOffset: pulumi.Int(0),
GroupId: pulumi.Int(0),
GroupOrder: pulumi.Int(0),
Locations: pulumi.StringArray{
pulumi.String("string"),
},
AlertSettings: &checkly.SslMonitorAlertSettingsArgs{
EscalationType: pulumi.String("string"),
ParallelRunFailureThresholds: checkly.SslMonitorAlertSettingsParallelRunFailureThresholdArray{
&checkly.SslMonitorAlertSettingsParallelRunFailureThresholdArgs{
Enabled: pulumi.Bool(false),
Percentage: pulumi.Int(0),
},
},
Reminders: checkly.SslMonitorAlertSettingsReminderArray{
&checkly.SslMonitorAlertSettingsReminderArgs{
Amount: pulumi.Int(0),
Interval: pulumi.Int(0),
},
},
RunBasedEscalations: checkly.SslMonitorAlertSettingsRunBasedEscalationArray{
&checkly.SslMonitorAlertSettingsRunBasedEscalationArgs{
FailedRunThreshold: pulumi.Int(0),
},
},
TimeBasedEscalations: checkly.SslMonitorAlertSettingsTimeBasedEscalationArray{
&checkly.SslMonitorAlertSettingsTimeBasedEscalationArgs{
MinutesFailingThreshold: pulumi.Int(0),
},
},
},
Muted: pulumi.Bool(false),
Description: pulumi.String("string"),
PrivateLocations: pulumi.StringArray{
pulumi.String("string"),
},
AlertChannelSubscriptions: checkly.SslMonitorAlertChannelSubscriptionArray{
&checkly.SslMonitorAlertChannelSubscriptionArgs{
Activated: pulumi.Bool(false),
ChannelId: pulumi.Int(0),
},
},
RetryStrategy: &checkly.SslMonitorRetryStrategyArgs{
Type: pulumi.String("string"),
BaseBackoffSeconds: pulumi.Int(0),
MaxDurationSeconds: pulumi.Int(0),
MaxRetries: pulumi.Int(0),
OnlyOn: &checkly.SslMonitorRetryStrategyOnlyOnArgs{},
SameRegion: pulumi.Bool(false),
},
RunParallel: pulumi.Bool(false),
RuntimeId: pulumi.String("string"),
ShouldFail: pulumi.Bool(false),
Tags: pulumi.StringArray{
pulumi.String("string"),
},
TriggerIncident: &checkly.SslMonitorTriggerIncidentArgs{
Description: pulumi.String("string"),
Name: pulumi.String("string"),
NotifySubscribers: pulumi.Bool(false),
ServiceId: pulumi.String("string"),
Severity: pulumi.String("string"),
},
UseGlobalAlertSettings: pulumi.Bool(false),
})
resource "checkly_ssl_monitor" "sslMonitorResource" {
lifecycle {
create_before_destroy = true
}
frequency = 0
request = {
hostname = "string"
alert_days_before_expiry = 0
assertions = [{
comparison = "string"
source = "string"
property = "string"
target = "string"
}]
client_certificate = {
client_certificate_id = "string"
mode = "string"
}
handshake_timeout_ms = 0
ip_family = "string"
port = 0
security_baseline = {
enabled = false
known_bad_ca = {
severity = "string"
}
min_key_size_bits = {
severity = "string"
value = 0
}
min_tls_version = {
severity = "string"
value = "string"
}
ocsp_must_staple_respected = {
severity = "string"
}
recommended_key_size_bits = {
severity = "string"
value = 0
}
recommended_tls_version = {
severity = "string"
value = "string"
}
sct_present = {
severity = "string"
}
weak_cipher_suite = {
severity = "string"
}
weak_signature_algorithm = {
severity = "string"
}
}
server_name = "string"
skip_chain_validation = false
}
activated = false
max_response_time = 0
name = "string"
degraded_response_time = 0
frequency_offset = 0
group_id = 0
group_order = 0
locations = ["string"]
alert_settings = {
escalation_type = "string"
parallel_run_failure_thresholds = [{
enabled = false
percentage = 0
}]
reminders = [{
amount = 0
interval = 0
}]
run_based_escalations = [{
failed_run_threshold = 0
}]
time_based_escalations = [{
minutes_failing_threshold = 0
}]
}
muted = false
description = "string"
private_locations = ["string"]
alert_channel_subscriptions {
activated = false
channel_id = 0
}
retry_strategy = {
type = "string"
base_backoff_seconds = 0
max_duration_seconds = 0
max_retries = 0
only_on = {}
same_region = false
}
run_parallel = false
runtime_id = "string"
should_fail = false
tags = ["string"]
trigger_incident = {
description = "string"
name = "string"
notify_subscribers = false
service_id = "string"
severity = "string"
}
use_global_alert_settings = false
}
var sslMonitorResource = new SslMonitor("sslMonitorResource", SslMonitorArgs.builder()
.frequency(0)
.request(SslMonitorRequestArgs.builder()
.hostname("string")
.alertDaysBeforeExpiry(0)
.assertions(SslMonitorRequestAssertionArgs.builder()
.comparison("string")
.source("string")
.property("string")
.target("string")
.build())
.clientCertificate(SslMonitorRequestClientCertificateArgs.builder()
.clientCertificateId("string")
.mode("string")
.build())
.handshakeTimeoutMs(0)
.ipFamily("string")
.port(0)
.securityBaseline(SslMonitorRequestSecurityBaselineArgs.builder()
.enabled(false)
.knownBadCa(SslMonitorRequestSecurityBaselineKnownBadCaArgs.builder()
.severity("string")
.build())
.minKeySizeBits(SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs.builder()
.severity("string")
.value(0)
.build())
.minTlsVersion(SslMonitorRequestSecurityBaselineMinTlsVersionArgs.builder()
.severity("string")
.value("string")
.build())
.ocspMustStapleRespected(SslMonitorRequestSecurityBaselineOcspMustStapleRespectedArgs.builder()
.severity("string")
.build())
.recommendedKeySizeBits(SslMonitorRequestSecurityBaselineRecommendedKeySizeBitsArgs.builder()
.severity("string")
.value(0)
.build())
.recommendedTlsVersion(SslMonitorRequestSecurityBaselineRecommendedTlsVersionArgs.builder()
.severity("string")
.value("string")
.build())
.sctPresent(SslMonitorRequestSecurityBaselineSctPresentArgs.builder()
.severity("string")
.build())
.weakCipherSuite(SslMonitorRequestSecurityBaselineWeakCipherSuiteArgs.builder()
.severity("string")
.build())
.weakSignatureAlgorithm(SslMonitorRequestSecurityBaselineWeakSignatureAlgorithmArgs.builder()
.severity("string")
.build())
.build())
.serverName("string")
.skipChainValidation(false)
.build())
.activated(false)
.maxResponseTime(0)
.name("string")
.degradedResponseTime(0)
.frequencyOffset(0)
.groupId(0)
.groupOrder(0)
.locations("string")
.alertSettings(SslMonitorAlertSettingsArgs.builder()
.escalationType("string")
.parallelRunFailureThresholds(SslMonitorAlertSettingsParallelRunFailureThresholdArgs.builder()
.enabled(false)
.percentage(0)
.build())
.reminders(SslMonitorAlertSettingsReminderArgs.builder()
.amount(0)
.interval(0)
.build())
.runBasedEscalations(SslMonitorAlertSettingsRunBasedEscalationArgs.builder()
.failedRunThreshold(0)
.build())
.timeBasedEscalations(SslMonitorAlertSettingsTimeBasedEscalationArgs.builder()
.minutesFailingThreshold(0)
.build())
.build())
.muted(false)
.description("string")
.privateLocations("string")
.alertChannelSubscriptions(SslMonitorAlertChannelSubscriptionArgs.builder()
.activated(false)
.channelId(0)
.build())
.retryStrategy(SslMonitorRetryStrategyArgs.builder()
.type("string")
.baseBackoffSeconds(0)
.maxDurationSeconds(0)
.maxRetries(0)
.onlyOn(SslMonitorRetryStrategyOnlyOnArgs.builder()
.build())
.sameRegion(false)
.build())
.runParallel(false)
.runtimeId("string")
.shouldFail(false)
.tags("string")
.triggerIncident(SslMonitorTriggerIncidentArgs.builder()
.description("string")
.name("string")
.notifySubscribers(false)
.serviceId("string")
.severity("string")
.build())
.useGlobalAlertSettings(false)
.build());
ssl_monitor_resource = checkly.SslMonitor("sslMonitorResource",
frequency=0,
request={
"hostname": "string",
"alert_days_before_expiry": 0,
"assertions": [{
"comparison": "string",
"source": "string",
"property": "string",
"target": "string",
}],
"client_certificate": {
"client_certificate_id": "string",
"mode": "string",
},
"handshake_timeout_ms": 0,
"ip_family": "string",
"port": 0,
"security_baseline": {
"enabled": False,
"known_bad_ca": {
"severity": "string",
},
"min_key_size_bits": {
"severity": "string",
"value": 0,
},
"min_tls_version": {
"severity": "string",
"value": "string",
},
"ocsp_must_staple_respected": {
"severity": "string",
},
"recommended_key_size_bits": {
"severity": "string",
"value": 0,
},
"recommended_tls_version": {
"severity": "string",
"value": "string",
},
"sct_present": {
"severity": "string",
},
"weak_cipher_suite": {
"severity": "string",
},
"weak_signature_algorithm": {
"severity": "string",
},
},
"server_name": "string",
"skip_chain_validation": False,
},
activated=False,
max_response_time=0,
name="string",
degraded_response_time=0,
frequency_offset=0,
group_id=0,
group_order=0,
locations=["string"],
alert_settings={
"escalation_type": "string",
"parallel_run_failure_thresholds": [{
"enabled": False,
"percentage": 0,
}],
"reminders": [{
"amount": 0,
"interval": 0,
}],
"run_based_escalations": [{
"failed_run_threshold": 0,
}],
"time_based_escalations": [{
"minutes_failing_threshold": 0,
}],
},
muted=False,
description="string",
private_locations=["string"],
alert_channel_subscriptions=[{
"activated": False,
"channel_id": 0,
}],
retry_strategy={
"type": "string",
"base_backoff_seconds": 0,
"max_duration_seconds": 0,
"max_retries": 0,
"only_on": {},
"same_region": False,
},
run_parallel=False,
runtime_id="string",
should_fail=False,
tags=["string"],
trigger_incident={
"description": "string",
"name": "string",
"notify_subscribers": False,
"service_id": "string",
"severity": "string",
},
use_global_alert_settings=False)
const sslMonitorResource = new checkly.SslMonitor("sslMonitorResource", {
frequency: 0,
request: {
hostname: "string",
alertDaysBeforeExpiry: 0,
assertions: [{
comparison: "string",
source: "string",
property: "string",
target: "string",
}],
clientCertificate: {
clientCertificateId: "string",
mode: "string",
},
handshakeTimeoutMs: 0,
ipFamily: "string",
port: 0,
securityBaseline: {
enabled: false,
knownBadCa: {
severity: "string",
},
minKeySizeBits: {
severity: "string",
value: 0,
},
minTlsVersion: {
severity: "string",
value: "string",
},
ocspMustStapleRespected: {
severity: "string",
},
recommendedKeySizeBits: {
severity: "string",
value: 0,
},
recommendedTlsVersion: {
severity: "string",
value: "string",
},
sctPresent: {
severity: "string",
},
weakCipherSuite: {
severity: "string",
},
weakSignatureAlgorithm: {
severity: "string",
},
},
serverName: "string",
skipChainValidation: false,
},
activated: false,
maxResponseTime: 0,
name: "string",
degradedResponseTime: 0,
frequencyOffset: 0,
groupId: 0,
groupOrder: 0,
locations: ["string"],
alertSettings: {
escalationType: "string",
parallelRunFailureThresholds: [{
enabled: false,
percentage: 0,
}],
reminders: [{
amount: 0,
interval: 0,
}],
runBasedEscalations: [{
failedRunThreshold: 0,
}],
timeBasedEscalations: [{
minutesFailingThreshold: 0,
}],
},
muted: false,
description: "string",
privateLocations: ["string"],
alertChannelSubscriptions: [{
activated: false,
channelId: 0,
}],
retryStrategy: {
type: "string",
baseBackoffSeconds: 0,
maxDurationSeconds: 0,
maxRetries: 0,
onlyOn: {},
sameRegion: false,
},
runParallel: false,
runtimeId: "string",
shouldFail: false,
tags: ["string"],
triggerIncident: {
description: "string",
name: "string",
notifySubscribers: false,
serviceId: "string",
severity: "string",
},
useGlobalAlertSettings: false,
});
type: checkly:SslMonitor
properties:
activated: false
alertChannelSubscriptions:
- activated: false
channelId: 0
alertSettings:
escalationType: string
parallelRunFailureThresholds:
- enabled: false
percentage: 0
reminders:
- amount: 0
interval: 0
runBasedEscalations:
- failedRunThreshold: 0
timeBasedEscalations:
- minutesFailingThreshold: 0
degradedResponseTime: 0
description: string
frequency: 0
frequencyOffset: 0
groupId: 0
groupOrder: 0
locations:
- string
maxResponseTime: 0
muted: false
name: string
privateLocations:
- string
request:
alertDaysBeforeExpiry: 0
assertions:
- comparison: string
property: string
source: string
target: string
clientCertificate:
clientCertificateId: string
mode: string
handshakeTimeoutMs: 0
hostname: string
ipFamily: string
port: 0
securityBaseline:
enabled: false
knownBadCa:
severity: string
minKeySizeBits:
severity: string
value: 0
minTlsVersion:
severity: string
value: string
ocspMustStapleRespected:
severity: string
recommendedKeySizeBits:
severity: string
value: 0
recommendedTlsVersion:
severity: string
value: string
sctPresent:
severity: string
weakCipherSuite:
severity: string
weakSignatureAlgorithm:
severity: string
serverName: string
skipChainValidation: false
retryStrategy:
baseBackoffSeconds: 0
maxDurationSeconds: 0
maxRetries: 0
onlyOn: {}
sameRegion: false
type: string
runParallel: false
runtimeId: string
shouldFail: false
tags:
- string
triggerIncident:
description: string
name: string
notifySubscribers: false
serviceId: string
severity: string
useGlobalAlertSettings: false
SslMonitor Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The SslMonitor resource accepts the following input properties:
- Activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - Frequency int
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - Request
Ssl
Monitor Request - The parameters for the SSL connection.
- Alert
Channel List<SslSubscriptions Monitor Alert Channel Subscription> - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- Alert
Settings SslMonitor Alert Settings - Determines the alert escalation policy for the monitor.
- Degraded
Response intTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - Description string
- A description of the monitor.
- Frequency
Offset int - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - Group
Id int - The id of the check group this monitor is part of.
- Group
Order int - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- Locations List<string>
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- Max
Response intTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - Muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- Name string
- The name of the monitor.
- Private
Locations List<string> - An array of one or more private locations slugs.
- Retry
Strategy SslMonitor Retry Strategy - A strategy for retrying failed check/monitor runs.
- Run
Parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- Runtime
Id string - The ID of the runtime to use for this monitor.
- Should
Fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- List<string>
- A list of tags for organizing and filtering checks and monitors.
- Trigger
Incident SslMonitor Trigger Incident - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- Use
Global boolAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- Activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - Frequency int
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - Request
Ssl
Monitor Request Args - The parameters for the SSL connection.
- Alert
Channel []SslSubscriptions Monitor Alert Channel Subscription Args - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- Alert
Settings SslMonitor Alert Settings Args - Determines the alert escalation policy for the monitor.
- Degraded
Response intTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - Description string
- A description of the monitor.
- Frequency
Offset int - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - Group
Id int - The id of the check group this monitor is part of.
- Group
Order int - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- Locations []string
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- Max
Response intTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - Muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- Name string
- The name of the monitor.
- Private
Locations []string - An array of one or more private locations slugs.
- Retry
Strategy SslMonitor Retry Strategy Args - A strategy for retrying failed check/monitor runs.
- Run
Parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- Runtime
Id string - The ID of the runtime to use for this monitor.
- Should
Fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- []string
- A list of tags for organizing and filtering checks and monitors.
- Trigger
Incident SslMonitor Trigger Incident Args - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- Use
Global boolAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - frequency number
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - request object
- The parameters for the SSL connection.
- alert_
channel_ list(object)subscriptions - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert_
settings object - Determines the alert escalation policy for the monitor.
- degraded_
response_ numbertime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description string
- A description of the monitor.
- frequency_
offset number - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group_
id number - The id of the check group this monitor is part of.
- group_
order number - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations list(string)
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max_
response_ numbertime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name string
- The name of the monitor.
- private_
locations list(string) - An array of one or more private locations slugs.
- retry_
strategy object - A strategy for retrying failed check/monitor runs.
- run_
parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime_
id string - The ID of the runtime to use for this monitor.
- should_
fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- list(string)
- A list of tags for organizing and filtering checks and monitors.
- trigger_
incident object - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use_
global_ boolalert_ settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated Boolean
- Determines if the monitor is running or not. Possible values
true, andfalse. - frequency Integer
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - request
Ssl
Monitor Request - The parameters for the SSL connection.
- alert
Channel List<SslSubscriptions Monitor Alert Channel Subscription> - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert
Settings SslMonitor Alert Settings - Determines the alert escalation policy for the monitor.
- degraded
Response IntegerTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description String
- A description of the monitor.
- frequency
Offset Integer - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group
Id Integer - The id of the check group this monitor is part of.
- group
Order Integer - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations List<String>
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max
Response IntegerTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted Boolean
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name String
- The name of the monitor.
- private
Locations List<String> - An array of one or more private locations slugs.
- retry
Strategy SslMonitor Retry Strategy - A strategy for retrying failed check/monitor runs.
- run
Parallel Boolean - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime
Id String - The ID of the runtime to use for this monitor.
- should
Fail Boolean - Allows to invert the behaviour of when a monitor is considered to fail.
- List<String>
- A list of tags for organizing and filtering checks and monitors.
- trigger
Incident SslMonitor Trigger Incident - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use
Global BooleanAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated boolean
- Determines if the monitor is running or not. Possible values
true, andfalse. - frequency number
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - request
Ssl
Monitor Request - The parameters for the SSL connection.
- alert
Channel SslSubscriptions Monitor Alert Channel Subscription[] - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert
Settings SslMonitor Alert Settings - Determines the alert escalation policy for the monitor.
- degraded
Response numberTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description string
- A description of the monitor.
- frequency
Offset number - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group
Id number - The id of the check group this monitor is part of.
- group
Order number - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations string[]
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max
Response numberTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted boolean
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name string
- The name of the monitor.
- private
Locations string[] - An array of one or more private locations slugs.
- retry
Strategy SslMonitor Retry Strategy - A strategy for retrying failed check/monitor runs.
- run
Parallel boolean - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime
Id string - The ID of the runtime to use for this monitor.
- should
Fail boolean - Allows to invert the behaviour of when a monitor is considered to fail.
- string[]
- A list of tags for organizing and filtering checks and monitors.
- trigger
Incident SslMonitor Trigger Incident - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use
Global booleanAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - frequency int
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - request
Ssl
Monitor Request Args - The parameters for the SSL connection.
- alert_
channel_ Sequence[Sslsubscriptions Monitor Alert Channel Subscription Args] - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert_
settings SslMonitor Alert Settings Args - Determines the alert escalation policy for the monitor.
- degraded_
response_ inttime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description str
- A description of the monitor.
- frequency_
offset int - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group_
id int - The id of the check group this monitor is part of.
- group_
order int - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations Sequence[str]
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max_
response_ inttime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name str
- The name of the monitor.
- private_
locations Sequence[str] - An array of one or more private locations slugs.
- retry_
strategy SslMonitor Retry Strategy Args - A strategy for retrying failed check/monitor runs.
- run_
parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime_
id str - The ID of the runtime to use for this monitor.
- should_
fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- Sequence[str]
- A list of tags for organizing and filtering checks and monitors.
- trigger_
incident SslMonitor Trigger Incident Args - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use_
global_ boolalert_ settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated Boolean
- Determines if the monitor is running or not. Possible values
true, andfalse. - frequency Number
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - request Property Map
- The parameters for the SSL connection.
- alert
Channel List<Property Map>Subscriptions - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert
Settings Property Map - Determines the alert escalation policy for the monitor.
- degraded
Response NumberTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description String
- A description of the monitor.
- frequency
Offset Number - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group
Id Number - The id of the check group this monitor is part of.
- group
Order Number - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations List<String>
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max
Response NumberTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted Boolean
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name String
- The name of the monitor.
- private
Locations List<String> - An array of one or more private locations slugs.
- retry
Strategy Property Map - A strategy for retrying failed check/monitor runs.
- run
Parallel Boolean - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime
Id String - The ID of the runtime to use for this monitor.
- should
Fail Boolean - Allows to invert the behaviour of when a monitor is considered to fail.
- List<String>
- A list of tags for organizing and filtering checks and monitors.
- trigger
Incident Property Map - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use
Global BooleanAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
Outputs
All input properties are implicitly available as output properties. Additionally, the SslMonitor resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing SslMonitor Resource
Get an existing SslMonitor resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: SslMonitorState, opts?: CustomResourceOptions): SslMonitor@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
activated: Optional[bool] = None,
alert_channel_subscriptions: Optional[Sequence[SslMonitorAlertChannelSubscriptionArgs]] = None,
alert_settings: Optional[SslMonitorAlertSettingsArgs] = None,
degraded_response_time: Optional[int] = None,
description: Optional[str] = None,
frequency: Optional[int] = None,
frequency_offset: Optional[int] = None,
group_id: Optional[int] = None,
group_order: Optional[int] = None,
locations: Optional[Sequence[str]] = None,
max_response_time: Optional[int] = None,
muted: Optional[bool] = None,
name: Optional[str] = None,
private_locations: Optional[Sequence[str]] = None,
request: Optional[SslMonitorRequestArgs] = None,
retry_strategy: Optional[SslMonitorRetryStrategyArgs] = None,
run_parallel: Optional[bool] = None,
runtime_id: Optional[str] = None,
should_fail: Optional[bool] = None,
tags: Optional[Sequence[str]] = None,
trigger_incident: Optional[SslMonitorTriggerIncidentArgs] = None,
use_global_alert_settings: Optional[bool] = None) -> SslMonitorfunc GetSslMonitor(ctx *Context, name string, id IDInput, state *SslMonitorState, opts ...ResourceOption) (*SslMonitor, error)public static SslMonitor Get(string name, Input<string> id, SslMonitorState? state, CustomResourceOptions? opts = null)public static SslMonitor get(String name, Output<String> id, SslMonitorState state, CustomResourceOptions options)resources: _: type: checkly:SslMonitor get: id: ${id}import {
to = checkly_ssl_monitor.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - Alert
Channel List<SslSubscriptions Monitor Alert Channel Subscription> - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- Alert
Settings SslMonitor Alert Settings - Determines the alert escalation policy for the monitor.
- Degraded
Response intTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - Description string
- A description of the monitor.
- Frequency int
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - Frequency
Offset int - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - Group
Id int - The id of the check group this monitor is part of.
- Group
Order int - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- Locations List<string>
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- Max
Response intTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - Muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- Name string
- The name of the monitor.
- Private
Locations List<string> - An array of one or more private locations slugs.
- Request
Ssl
Monitor Request - The parameters for the SSL connection.
- Retry
Strategy SslMonitor Retry Strategy - A strategy for retrying failed check/monitor runs.
- Run
Parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- Runtime
Id string - The ID of the runtime to use for this monitor.
- Should
Fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- List<string>
- A list of tags for organizing and filtering checks and monitors.
- Trigger
Incident SslMonitor Trigger Incident - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- Use
Global boolAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- Activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - Alert
Channel []SslSubscriptions Monitor Alert Channel Subscription Args - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- Alert
Settings SslMonitor Alert Settings Args - Determines the alert escalation policy for the monitor.
- Degraded
Response intTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - Description string
- A description of the monitor.
- Frequency int
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - Frequency
Offset int - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - Group
Id int - The id of the check group this monitor is part of.
- Group
Order int - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- Locations []string
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- Max
Response intTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - Muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- Name string
- The name of the monitor.
- Private
Locations []string - An array of one or more private locations slugs.
- Request
Ssl
Monitor Request Args - The parameters for the SSL connection.
- Retry
Strategy SslMonitor Retry Strategy Args - A strategy for retrying failed check/monitor runs.
- Run
Parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- Runtime
Id string - The ID of the runtime to use for this monitor.
- Should
Fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- []string
- A list of tags for organizing and filtering checks and monitors.
- Trigger
Incident SslMonitor Trigger Incident Args - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- Use
Global boolAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - alert_
channel_ list(object)subscriptions - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert_
settings object - Determines the alert escalation policy for the monitor.
- degraded_
response_ numbertime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description string
- A description of the monitor.
- frequency number
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - frequency_
offset number - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group_
id number - The id of the check group this monitor is part of.
- group_
order number - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations list(string)
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max_
response_ numbertime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name string
- The name of the monitor.
- private_
locations list(string) - An array of one or more private locations slugs.
- request object
- The parameters for the SSL connection.
- retry_
strategy object - A strategy for retrying failed check/monitor runs.
- run_
parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime_
id string - The ID of the runtime to use for this monitor.
- should_
fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- list(string)
- A list of tags for organizing and filtering checks and monitors.
- trigger_
incident object - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use_
global_ boolalert_ settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated Boolean
- Determines if the monitor is running or not. Possible values
true, andfalse. - alert
Channel List<SslSubscriptions Monitor Alert Channel Subscription> - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert
Settings SslMonitor Alert Settings - Determines the alert escalation policy for the monitor.
- degraded
Response IntegerTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description String
- A description of the monitor.
- frequency Integer
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - frequency
Offset Integer - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group
Id Integer - The id of the check group this monitor is part of.
- group
Order Integer - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations List<String>
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max
Response IntegerTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted Boolean
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name String
- The name of the monitor.
- private
Locations List<String> - An array of one or more private locations slugs.
- request
Ssl
Monitor Request - The parameters for the SSL connection.
- retry
Strategy SslMonitor Retry Strategy - A strategy for retrying failed check/monitor runs.
- run
Parallel Boolean - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime
Id String - The ID of the runtime to use for this monitor.
- should
Fail Boolean - Allows to invert the behaviour of when a monitor is considered to fail.
- List<String>
- A list of tags for organizing and filtering checks and monitors.
- trigger
Incident SslMonitor Trigger Incident - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use
Global BooleanAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated boolean
- Determines if the monitor is running or not. Possible values
true, andfalse. - alert
Channel SslSubscriptions Monitor Alert Channel Subscription[] - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert
Settings SslMonitor Alert Settings - Determines the alert escalation policy for the monitor.
- degraded
Response numberTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description string
- A description of the monitor.
- frequency number
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - frequency
Offset number - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group
Id number - The id of the check group this monitor is part of.
- group
Order number - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations string[]
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max
Response numberTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted boolean
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name string
- The name of the monitor.
- private
Locations string[] - An array of one or more private locations slugs.
- request
Ssl
Monitor Request - The parameters for the SSL connection.
- retry
Strategy SslMonitor Retry Strategy - A strategy for retrying failed check/monitor runs.
- run
Parallel boolean - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime
Id string - The ID of the runtime to use for this monitor.
- should
Fail boolean - Allows to invert the behaviour of when a monitor is considered to fail.
- string[]
- A list of tags for organizing and filtering checks and monitors.
- trigger
Incident SslMonitor Trigger Incident - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use
Global booleanAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated bool
- Determines if the monitor is running or not. Possible values
true, andfalse. - alert_
channel_ Sequence[Sslsubscriptions Monitor Alert Channel Subscription Args] - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert_
settings SslMonitor Alert Settings Args - Determines the alert escalation policy for the monitor.
- degraded_
response_ inttime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description str
- A description of the monitor.
- frequency int
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - frequency_
offset int - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group_
id int - The id of the check group this monitor is part of.
- group_
order int - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations Sequence[str]
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max_
response_ inttime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted bool
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name str
- The name of the monitor.
- private_
locations Sequence[str] - An array of one or more private locations slugs.
- request
Ssl
Monitor Request Args - The parameters for the SSL connection.
- retry_
strategy SslMonitor Retry Strategy Args - A strategy for retrying failed check/monitor runs.
- run_
parallel bool - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime_
id str - The ID of the runtime to use for this monitor.
- should_
fail bool - Allows to invert the behaviour of when a monitor is considered to fail.
- Sequence[str]
- A list of tags for organizing and filtering checks and monitors.
- trigger_
incident SslMonitor Trigger Incident Args - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use_
global_ boolalert_ settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
- activated Boolean
- Determines if the monitor is running or not. Possible values
true, andfalse. - alert
Channel List<Property Map>Subscriptions - An array of channel IDs and whether they're activated or not. If you don't set at least one alert channel subscription for your monitor, we won't be able to alert you even if it starts failing.
- alert
Settings Property Map - Determines the alert escalation policy for the monitor.
- degraded
Response NumberTime - The handshake time in milliseconds above which the monitor is considered degraded. Possible values are between 0 and 30000. (Default
10000). - description String
- A description of the monitor.
- frequency Number
- Controls how often the monitor should run. Defined in minutes. The allowed values are
0(high frequency - usefrequency_offsetto define the actual frequency),1(1 minute),2(2 minutes),5(5 minutes),10(10 minutes),15(15 minutes),30(30 minutes),60(1 hour),120(2 hours),180(3 hours),360(6 hours),720(12 hours) and1440(24 hours). - frequency
Offset Number - When
frequencyis0(high frequency),frequency_offsetis required and it alone controls how often the monitor should run. Defined in seconds. The allowed values are0(disabled - usefrequencyto define the actual frequency),10(10 seconds),20(20 seconds) and30(30 seconds). - group
Id Number - The id of the check group this monitor is part of.
- group
Order Number - The position of this monitor in a check group. It determines in what order checks and monitors are run when a group is triggered from the API or from CI/CD.
- locations List<String>
- An array of one or more data center locations where to run this monitor. (Default ["us-east-1"])
- max
Response NumberTime - The handshake time in milliseconds above which the monitor is considered failing. Must be greater than or equal to
degraded_response_time. Possible values are between 0 and 30000. (Default20000). - muted Boolean
- Determines if any notifications will be sent out when a monitor fails/degrades/recovers.
- name String
- The name of the monitor.
- private
Locations List<String> - An array of one or more private locations slugs.
- request Property Map
- The parameters for the SSL connection.
- retry
Strategy Property Map - A strategy for retrying failed check/monitor runs.
- run
Parallel Boolean - Determines if the monitor should run in all selected locations in parallel or round-robin.
- runtime
Id String - The ID of the runtime to use for this monitor.
- should
Fail Boolean - Allows to invert the behaviour of when a monitor is considered to fail.
- List<String>
- A list of tags for organizing and filtering checks and monitors.
- trigger
Incident Property Map - Create and resolve an incident based on the alert configuration. Useful for status page automation.
- use
Global BooleanAlert Settings - When true, the account level alert settings will be used, not the alert setting defined on this monitor.
Supporting Types
SslMonitorAlertChannelSubscription, SslMonitorAlertChannelSubscriptionArgs
- activated bool
- Whether an alert should be sent to this channel.
- channel_
id number - The ID of the alert channel.
- activated bool
- Whether an alert should be sent to this channel.
- channel_
id int - The ID of the alert channel.
SslMonitorAlertSettings, SslMonitorAlertSettingsArgs
- Escalation
Type string - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - Parallel
Run List<SslFailure Thresholds Monitor Alert Settings Parallel Run Failure Threshold> - Configuration for parallel run failure threshold.
- Reminders
List<Ssl
Monitor Alert Settings Reminder> - Defines how often to send reminder notifications after initial alert.
- Run
Based List<SslEscalations Monitor Alert Settings Run Based Escalation> - Configuration for run-based escalation.
- Time
Based List<SslEscalations Monitor Alert Settings Time Based Escalation> - Configuration for time-based escalation.
- Escalation
Type string - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - Parallel
Run []SslFailure Thresholds Monitor Alert Settings Parallel Run Failure Threshold - Configuration for parallel run failure threshold.
- Reminders
[]Ssl
Monitor Alert Settings Reminder - Defines how often to send reminder notifications after initial alert.
- Run
Based []SslEscalations Monitor Alert Settings Run Based Escalation - Configuration for run-based escalation.
- Time
Based []SslEscalations Monitor Alert Settings Time Based Escalation - Configuration for time-based escalation.
- escalation_
type string - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - parallel_
run_ list(object)failure_ thresholds - Configuration for parallel run failure threshold.
- reminders list(object)
- Defines how often to send reminder notifications after initial alert.
- run_
based_ list(object)escalations - Configuration for run-based escalation.
- time_
based_ list(object)escalations - Configuration for time-based escalation.
- escalation
Type String - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - parallel
Run List<SslFailure Thresholds Monitor Alert Settings Parallel Run Failure Threshold> - Configuration for parallel run failure threshold.
- reminders
List<Ssl
Monitor Alert Settings Reminder> - Defines how often to send reminder notifications after initial alert.
- run
Based List<SslEscalations Monitor Alert Settings Run Based Escalation> - Configuration for run-based escalation.
- time
Based List<SslEscalations Monitor Alert Settings Time Based Escalation> - Configuration for time-based escalation.
- escalation
Type string - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - parallel
Run SslFailure Thresholds Monitor Alert Settings Parallel Run Failure Threshold[] - Configuration for parallel run failure threshold.
- reminders
Ssl
Monitor Alert Settings Reminder[] - Defines how often to send reminder notifications after initial alert.
- run
Based SslEscalations Monitor Alert Settings Run Based Escalation[] - Configuration for run-based escalation.
- time
Based SslEscalations Monitor Alert Settings Time Based Escalation[] - Configuration for time-based escalation.
- escalation_
type str - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - parallel_
run_ Sequence[Sslfailure_ thresholds Monitor Alert Settings Parallel Run Failure Threshold] - Configuration for parallel run failure threshold.
- reminders
Sequence[Ssl
Monitor Alert Settings Reminder] - Defines how often to send reminder notifications after initial alert.
- run_
based_ Sequence[Sslescalations Monitor Alert Settings Run Based Escalation] - Configuration for run-based escalation.
- time_
based_ Sequence[Sslescalations Monitor Alert Settings Time Based Escalation] - Configuration for time-based escalation.
- escalation
Type String - Determines the type of escalation to use. Possible values are
RUN_BASEDandTIME_BASED. (DefaultRUN_BASED). - parallel
Run List<Property Map>Failure Thresholds - Configuration for parallel run failure threshold.
- reminders List<Property Map>
- Defines how often to send reminder notifications after initial alert.
- run
Based List<Property Map>Escalations - Configuration for run-based escalation.
- time
Based List<Property Map>Escalations - Configuration for time-based escalation.
SslMonitorAlertSettingsParallelRunFailureThreshold, SslMonitorAlertSettingsParallelRunFailureThresholdArgs
- Enabled bool
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - Percentage int
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
- Enabled bool
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - Percentage int
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
- enabled bool
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - percentage number
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
- enabled Boolean
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - percentage Integer
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
- enabled boolean
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - percentage number
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
- enabled bool
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - percentage int
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
- enabled Boolean
- Whether parallel run failure threshold is enabled. Only applies if the monitor is scheduled for multiple locations in parallel. (Default
false). - percentage Number
- Percentage of runs that must fail to trigger alert. Possible values are
10,20,30,40,50,60,70,80,90, and100. (Default10).
SslMonitorAlertSettingsReminder, SslMonitorAlertSettingsReminderArgs
SslMonitorAlertSettingsRunBasedEscalation, SslMonitorAlertSettingsRunBasedEscalationArgs
- Failed
Run intThreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
- Failed
Run intThreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
- failed_
run_ numberthreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
- failed
Run IntegerThreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
- failed
Run numberThreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
- failed_
run_ intthreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
- failed
Run NumberThreshold - Send an alert notification after the given number of consecutive monitor runs have failed. Possible values are between
1and5. (Default1).
SslMonitorAlertSettingsTimeBasedEscalation, SslMonitorAlertSettingsTimeBasedEscalationArgs
- Minutes
Failing intThreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
- Minutes
Failing intThreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
- minutes_
failing_ numberthreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
- minutes
Failing IntegerThreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
- minutes
Failing numberThreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
- minutes_
failing_ intthreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
- minutes
Failing NumberThreshold - Send an alert notification after the monitor has been failing for the given amount of time (in minutes). Possible values are
5,10,15, and30. (Default5).
SslMonitorRequest, SslMonitorRequestArgs
- Hostname string
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- Alert
Days intBefore Expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - Assertions
List<Ssl
Monitor Request Assertion> - A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- Client
Certificate SslMonitor Request Client Certificate - The mutual-TLS client certificate configuration.
- Handshake
Timeout intMs - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - Ip
Family string - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - Port int
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - Security
Baseline SslMonitor Request Security Baseline - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - Server
Name string - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - Skip
Chain boolValidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
- Hostname string
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- Alert
Days intBefore Expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - Assertions
[]Ssl
Monitor Request Assertion - A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- Client
Certificate SslMonitor Request Client Certificate - The mutual-TLS client certificate configuration.
- Handshake
Timeout intMs - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - Ip
Family string - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - Port int
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - Security
Baseline SslMonitor Request Security Baseline - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - Server
Name string - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - Skip
Chain boolValidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
- hostname string
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- alert_
days_ numberbefore_ expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - assertions list(object)
- A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- client_
certificate object - The mutual-TLS client certificate configuration.
- handshake_
timeout_ numberms - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - ip_
family string - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - port number
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - security_
baseline object - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - server_
name string - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - skip_
chain_ boolvalidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
- hostname String
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- alert
Days IntegerBefore Expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - assertions
List<Ssl
Monitor Request Assertion> - A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- client
Certificate SslMonitor Request Client Certificate - The mutual-TLS client certificate configuration.
- handshake
Timeout IntegerMs - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - ip
Family String - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - port Integer
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - security
Baseline SslMonitor Request Security Baseline - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - server
Name String - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - skip
Chain BooleanValidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
- hostname string
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- alert
Days numberBefore Expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - assertions
Ssl
Monitor Request Assertion[] - A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- client
Certificate SslMonitor Request Client Certificate - The mutual-TLS client certificate configuration.
- handshake
Timeout numberMs - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - ip
Family string - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - port number
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - security
Baseline SslMonitor Request Security Baseline - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - server
Name string - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - skip
Chain booleanValidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
- hostname str
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- alert_
days_ intbefore_ expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - assertions
Sequence[Ssl
Monitor Request Assertion] - A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- client_
certificate SslMonitor Request Client Certificate - The mutual-TLS client certificate configuration.
- handshake_
timeout_ intms - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - ip_
family str - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - port int
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - security_
baseline SslMonitor Request Security Baseline - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - server_
name str - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - skip_
chain_ boolvalidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
- hostname String
- The hostname to connect to and validate the TLS certificate of. Do not include a scheme or a port in this value.
- alert
Days NumberBefore Expiry - Raise an alert when the certificate is within this many days of expiry. Possible values are between 1 and 365. (Default
20). - assertions List<Property Map>
- A request can have multiple assertions. The allowed comparisons, properties, and target formats depend on the assertion source — see the Assertion Reference below.
- client
Certificate Property Map - The mutual-TLS client certificate configuration.
- handshake
Timeout NumberMs - The number of milliseconds to wait for the TLS handshake to complete before timing out. Possible values are between 1000 and 30000. (Default
10000). - ip
Family String - The IP family to use when executing the check. The value can be either
IPv4orIPv6. (DefaultIPv4). - port Number
- The port number to connect to. Possible values are between 1 and 65535. (Default
443). - security
Baseline Property Map - The SSL security baseline — a set of enforceable and advisory rules. Omit the block to inherit the account default baseline. Rules that are not listed keep their server defaults; removing a rule (or the whole block) resets it to its default on the next apply. Only listed rules are drift-checked: an external change to an unlisted rule is not shown by
pulumi previewand is reset on the next apply. - server
Name String - An optional SNI server name to send in the TLS handshake. Defaults to
hostnamewhen unset. - skip
Chain BooleanValidation - When true, the certificate chain is not validated against trusted roots (the certificate is still inspected for expiry and the security baseline). (Default
false).
SslMonitorRequestAssertion, SslMonitorRequestAssertionArgs
- Comparison string
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - Source string
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - Property string
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - Target string
- Comparison string
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - Source string
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - Property string
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - Target string
- comparison string
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - source string
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - property string
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - target string
- comparison String
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - source String
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - property String
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - target String
- comparison string
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - source string
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - property string
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - target string
- comparison str
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - source str
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - property str
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - target str
- comparison String
- The type of comparison to be executed between expected and actual value of the assertion. Possible values are
EQUALS,NOT_EQUALS,IS_EMPTY,NOT_EMPTY,GREATER_THAN,LESS_THAN,CONTAINS,NOT_CONTAINS,IS_NULL, andNOT_NULL. The allowed set depends on the assertedsourceandproperty; for example, boolean properties such aschainTrustedonly allowEQUALS. - source String
- The source of the asserted value. Possible values are
CERTIFICATE,CONNECTION,RESPONSE_TIME,JSON_RESPONSE, andTEXT_RESPONSE. - property String
- The property selecting the asserted value within the source. For
CERTIFICATE:daysUntilExpiry,keySizeBits,subjectCN,issuerCN,serialNumber,fingerprintSha256,issuerFingerprintSha256,keyAlgorithm,signatureAlgorithm,sans,selfSigned, orisCA. ForCONNECTION:tlsVersion,cipherSuite,hostnameVerified,chainTrusted,ocspStapled,ocspStatus, orresolvedIp. ForJSON_RESPONSE: a JSONPath expression. ForTEXT_RESPONSE: a regular expression applied to the serialized response. - target String
SslMonitorRequestClientCertificate, SslMonitorRequestClientCertificateArgs
- Client
Certificate stringId - The ID of the stored client certificate to present. Required when
mode = "explicit". - Mode string
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
- Client
Certificate stringId - The ID of the stored client certificate to present. Required when
mode = "explicit". - Mode string
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
- client_
certificate_ stringid - The ID of the stored client certificate to present. Required when
mode = "explicit". - mode string
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
- client
Certificate StringId - The ID of the stored client certificate to present. Required when
mode = "explicit". - mode String
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
- client
Certificate stringId - The ID of the stored client certificate to present. Required when
mode = "explicit". - mode string
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
- client_
certificate_ strid - The ID of the stored client certificate to present. Required when
mode = "explicit". - mode str
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
- client
Certificate StringId - The ID of the stored client certificate to present. Required when
mode = "explicit". - mode String
- The mutual-TLS client-certificate mode.
account_defaultinherits the account setting (no certificate sent),autolets Checkly select a stored certificate,explicituses the certificate referenced byclient_certificate_id. (Defaultaccount_default).
SslMonitorRequestSecurityBaseline, SslMonitorRequestSecurityBaselineArgs
- Enabled bool
- Whether the security baseline is enforced. (Default
true). - Known
Bad SslCa Monitor Request Security Baseline Known Bad Ca - Enforceable rule: the certificate chain must not include a known-bad CA.
- Min
Key SslSize Bits Monitor Request Security Baseline Min Key Size Bits - Enforceable rule: the minimum public key size in bits.
- Min
Tls SslVersion Monitor Request Security Baseline Min Tls Version - Enforceable rule: the minimum TLS version the server must accept.
- Ocsp
Must SslStaple Respected Monitor Request Security Baseline Ocsp Must Staple Respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- Recommended
Key SslSize Bits Monitor Request Security Baseline Recommended Key Size Bits - Advisory rule: the recommended public key size in bits.
- Recommended
Tls SslVersion Monitor Request Security Baseline Recommended Tls Version - Advisory rule: the recommended TLS version.
- Sct
Present SslMonitor Request Security Baseline Sct Present - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- Weak
Cipher SslSuite Monitor Request Security Baseline Weak Cipher Suite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- Weak
Signature SslAlgorithm Monitor Request Security Baseline Weak Signature Algorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
- Enabled bool
- Whether the security baseline is enforced. (Default
true). - Known
Bad SslCa Monitor Request Security Baseline Known Bad Ca - Enforceable rule: the certificate chain must not include a known-bad CA.
- Min
Key SslSize Bits Monitor Request Security Baseline Min Key Size Bits - Enforceable rule: the minimum public key size in bits.
- Min
Tls SslVersion Monitor Request Security Baseline Min Tls Version - Enforceable rule: the minimum TLS version the server must accept.
- Ocsp
Must SslStaple Respected Monitor Request Security Baseline Ocsp Must Staple Respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- Recommended
Key SslSize Bits Monitor Request Security Baseline Recommended Key Size Bits - Advisory rule: the recommended public key size in bits.
- Recommended
Tls SslVersion Monitor Request Security Baseline Recommended Tls Version - Advisory rule: the recommended TLS version.
- Sct
Present SslMonitor Request Security Baseline Sct Present - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- Weak
Cipher SslSuite Monitor Request Security Baseline Weak Cipher Suite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- Weak
Signature SslAlgorithm Monitor Request Security Baseline Weak Signature Algorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
- enabled bool
- Whether the security baseline is enforced. (Default
true). - known_
bad_ objectca - Enforceable rule: the certificate chain must not include a known-bad CA.
- min_
key_ objectsize_ bits - Enforceable rule: the minimum public key size in bits.
- min_
tls_ objectversion - Enforceable rule: the minimum TLS version the server must accept.
- ocsp_
must_ objectstaple_ respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- recommended_
key_ objectsize_ bits - Advisory rule: the recommended public key size in bits.
- recommended_
tls_ objectversion - Advisory rule: the recommended TLS version.
- sct_
present object - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- weak_
cipher_ objectsuite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- weak_
signature_ objectalgorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
- enabled Boolean
- Whether the security baseline is enforced. (Default
true). - known
Bad SslCa Monitor Request Security Baseline Known Bad Ca - Enforceable rule: the certificate chain must not include a known-bad CA.
- min
Key SslSize Bits Monitor Request Security Baseline Min Key Size Bits - Enforceable rule: the minimum public key size in bits.
- min
Tls SslVersion Monitor Request Security Baseline Min Tls Version - Enforceable rule: the minimum TLS version the server must accept.
- ocsp
Must SslStaple Respected Monitor Request Security Baseline Ocsp Must Staple Respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- recommended
Key SslSize Bits Monitor Request Security Baseline Recommended Key Size Bits - Advisory rule: the recommended public key size in bits.
- recommended
Tls SslVersion Monitor Request Security Baseline Recommended Tls Version - Advisory rule: the recommended TLS version.
- sct
Present SslMonitor Request Security Baseline Sct Present - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- weak
Cipher SslSuite Monitor Request Security Baseline Weak Cipher Suite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- weak
Signature SslAlgorithm Monitor Request Security Baseline Weak Signature Algorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
- enabled boolean
- Whether the security baseline is enforced. (Default
true). - known
Bad SslCa Monitor Request Security Baseline Known Bad Ca - Enforceable rule: the certificate chain must not include a known-bad CA.
- min
Key SslSize Bits Monitor Request Security Baseline Min Key Size Bits - Enforceable rule: the minimum public key size in bits.
- min
Tls SslVersion Monitor Request Security Baseline Min Tls Version - Enforceable rule: the minimum TLS version the server must accept.
- ocsp
Must SslStaple Respected Monitor Request Security Baseline Ocsp Must Staple Respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- recommended
Key SslSize Bits Monitor Request Security Baseline Recommended Key Size Bits - Advisory rule: the recommended public key size in bits.
- recommended
Tls SslVersion Monitor Request Security Baseline Recommended Tls Version - Advisory rule: the recommended TLS version.
- sct
Present SslMonitor Request Security Baseline Sct Present - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- weak
Cipher SslSuite Monitor Request Security Baseline Weak Cipher Suite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- weak
Signature SslAlgorithm Monitor Request Security Baseline Weak Signature Algorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
- enabled bool
- Whether the security baseline is enforced. (Default
true). - known_
bad_ Sslca Monitor Request Security Baseline Known Bad Ca - Enforceable rule: the certificate chain must not include a known-bad CA.
- min_
key_ Sslsize_ bits Monitor Request Security Baseline Min Key Size Bits - Enforceable rule: the minimum public key size in bits.
- min_
tls_ Sslversion Monitor Request Security Baseline Min Tls Version - Enforceable rule: the minimum TLS version the server must accept.
- ocsp_
must_ Sslstaple_ respected Monitor Request Security Baseline Ocsp Must Staple Respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- recommended_
key_ Sslsize_ bits Monitor Request Security Baseline Recommended Key Size Bits - Advisory rule: the recommended public key size in bits.
- recommended_
tls_ Sslversion Monitor Request Security Baseline Recommended Tls Version - Advisory rule: the recommended TLS version.
- sct_
present SslMonitor Request Security Baseline Sct Present - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- weak_
cipher_ Sslsuite Monitor Request Security Baseline Weak Cipher Suite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- weak_
signature_ Sslalgorithm Monitor Request Security Baseline Weak Signature Algorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
- enabled Boolean
- Whether the security baseline is enforced. (Default
true). - known
Bad Property MapCa - Enforceable rule: the certificate chain must not include a known-bad CA.
- min
Key Property MapSize Bits - Enforceable rule: the minimum public key size in bits.
- min
Tls Property MapVersion - Enforceable rule: the minimum TLS version the server must accept.
- ocsp
Must Property MapStaple Respected - Advisory rule: an OCSP Must-Staple extension, when present, must be respected.
- recommended
Key Property MapSize Bits - Advisory rule: the recommended public key size in bits.
- recommended
Tls Property MapVersion - Advisory rule: the recommended TLS version.
- sct
Present Property Map - Advisory rule: the certificate should carry a Signed Certificate Timestamp.
- weak
Cipher Property MapSuite - Enforceable rule: the connection must not negotiate a weak cipher suite.
- weak
Signature Property MapAlgorithm - Enforceable rule: the certificate must not use a weak signature algorithm.
SslMonitorRequestSecurityBaselineKnownBadCa, SslMonitorRequestSecurityBaselineKnownBadCaArgs
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity str
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
SslMonitorRequestSecurityBaselineMinKeySizeBits, SslMonitorRequestSecurityBaselineMinKeySizeBitsArgs
SslMonitorRequestSecurityBaselineMinTlsVersion, SslMonitorRequestSecurityBaselineMinTlsVersionArgs
SslMonitorRequestSecurityBaselineOcspMustStapleRespected, SslMonitorRequestSecurityBaselineOcspMustStapleRespectedArgs
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity str
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
SslMonitorRequestSecurityBaselineRecommendedKeySizeBits, SslMonitorRequestSecurityBaselineRecommendedKeySizeBitsArgs
SslMonitorRequestSecurityBaselineRecommendedTlsVersion, SslMonitorRequestSecurityBaselineRecommendedTlsVersionArgs
SslMonitorRequestSecurityBaselineSctPresent, SslMonitorRequestSecurityBaselineSctPresentArgs
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity str
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultignore).
SslMonitorRequestSecurityBaselineWeakCipherSuite, SslMonitorRequestSecurityBaselineWeakCipherSuiteArgs
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity str
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
SslMonitorRequestSecurityBaselineWeakSignatureAlgorithm, SslMonitorRequestSecurityBaselineWeakSignatureAlgorithmArgs
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- Severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity string
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity str
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
- severity String
- What happens when the rule is violated:
failfails the monitor,degrademarks it degraded,ignoredisables the rule. (Defaultfail).
SslMonitorRetryStrategy, SslMonitorRetryStrategyArgs
- Type string
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - Base
Backoff intSeconds - The number of seconds to wait before the first retry attempt. (Default
60). - Max
Duration intSeconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - Max
Retries int - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - Only
On SslMonitor Retry Strategy Only On - Apply the retry strategy only if the defined conditions match.
- Same
Region bool - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
- Type string
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - Base
Backoff intSeconds - The number of seconds to wait before the first retry attempt. (Default
60). - Max
Duration intSeconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - Max
Retries int - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - Only
On SslMonitor Retry Strategy Only On - Apply the retry strategy only if the defined conditions match.
- Same
Region bool - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
- type string
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - base_
backoff_ numberseconds - The number of seconds to wait before the first retry attempt. (Default
60). - max_
duration_ numberseconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - max_
retries number - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - only_
on object - Apply the retry strategy only if the defined conditions match.
- same_
region bool - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
- type String
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - base
Backoff IntegerSeconds - The number of seconds to wait before the first retry attempt. (Default
60). - max
Duration IntegerSeconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - max
Retries Integer - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - only
On SslMonitor Retry Strategy Only On - Apply the retry strategy only if the defined conditions match.
- same
Region Boolean - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
- type string
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - base
Backoff numberSeconds - The number of seconds to wait before the first retry attempt. (Default
60). - max
Duration numberSeconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - max
Retries number - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - only
On SslMonitor Retry Strategy Only On - Apply the retry strategy only if the defined conditions match.
- same
Region boolean - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
- type str
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - base_
backoff_ intseconds - The number of seconds to wait before the first retry attempt. (Default
60). - max_
duration_ intseconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - max_
retries int - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - only_
on SslMonitor Retry Strategy Only On - Apply the retry strategy only if the defined conditions match.
- same_
region bool - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
- type String
- Determines which type of retry strategy to use. Possible values are
FIXED,LINEAR,EXPONENTIAL,SINGLE_RETRY, andNO_RETRIES. - base
Backoff NumberSeconds - The number of seconds to wait before the first retry attempt. (Default
60). - max
Duration NumberSeconds - The total amount of time to continue retrying the check/monitor (maximum 600 seconds). Available when
typeisFIXED,LINEAR, orEXPONENTIAL. (Default600). - max
Retries Number - The maximum number of times to retry the check/monitor. Value must be between
1and10. Available whentypeisFIXED,LINEAR, orEXPONENTIAL. (Default2). - only
On Property Map - Apply the retry strategy only if the defined conditions match.
- same
Region Boolean - Whether retries should be run in the same region as the initial check/monitor run. (Default
true).
SslMonitorTriggerIncident, SslMonitorTriggerIncidentArgs
- Description string
- A detailed description of the incident.
- Name string
- The name of the incident.
- Notify
Subscribers bool - Whether to notify subscribers when the incident is triggered.
- Service
Id string - The status page service that this incident will be associated with.
- Severity string
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
- Description string
- A detailed description of the incident.
- Name string
- The name of the incident.
- Notify
Subscribers bool - Whether to notify subscribers when the incident is triggered.
- Service
Id string - The status page service that this incident will be associated with.
- Severity string
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
- description string
- A detailed description of the incident.
- name string
- The name of the incident.
- notify_
subscribers bool - Whether to notify subscribers when the incident is triggered.
- service_
id string - The status page service that this incident will be associated with.
- severity string
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
- description String
- A detailed description of the incident.
- name String
- The name of the incident.
- notify
Subscribers Boolean - Whether to notify subscribers when the incident is triggered.
- service
Id String - The status page service that this incident will be associated with.
- severity String
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
- description string
- A detailed description of the incident.
- name string
- The name of the incident.
- notify
Subscribers boolean - Whether to notify subscribers when the incident is triggered.
- service
Id string - The status page service that this incident will be associated with.
- severity string
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
- description str
- A detailed description of the incident.
- name str
- The name of the incident.
- notify_
subscribers bool - Whether to notify subscribers when the incident is triggered.
- service_
id str - The status page service that this incident will be associated with.
- severity str
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
- description String
- A detailed description of the incident.
- name String
- The name of the incident.
- notify
Subscribers Boolean - Whether to notify subscribers when the incident is triggered.
- service
Id String - The status page service that this incident will be associated with.
- severity String
- The severity level of the incident. Possible values are
MINOR,MEDIUM,MAJOR, andCRITICAL.
Package Details
- Repository
- checkly checkly/pulumi-checkly
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
checklyTerraform Provider.
published on Thursday, Sep 17, 2026 by Checkly