published on Tuesday, Sep 29, 2026 by civo
published on Tuesday, Sep 29, 2026 by civo
Provides a Civo firewall resource. This can be used to create, modify, and delete firewalls.
Example Usage
- View firewalls after creation on the CLI:
civo firewall ls
civo firewall rule ls example-firewall
Custom ingress and egress rules firewall
import * as pulumi from "@pulumi/pulumi";
import * as civo from "@pulumi/civo";
const example = new civo.VpcNetwork("example", {label: "example-network"});
const exampleVpcFirewall = new civo.VpcFirewall("example", {
name: "example-firewall",
networkId: example.vpcNetworkId,
createDefaultRules: false,
ingressRules: [
{
label: "http",
protocol: "tcp",
portRange: "80",
cidrs: ["0.0.0.0"],
action: "allow",
},
{
label: "https",
protocol: "tcp",
portRange: "443",
cidrs: ["0.0.0.0"],
action: "allow",
},
{
label: "ssh",
protocol: "tcp",
portRange: "22",
cidrs: [
"192.168.1.1/32",
"192.168.10.4/32",
"192.168.10.10/32",
],
action: "allow",
},
],
egressRules: [{
label: "all",
protocol: "tcp",
portRange: "1-65535",
cidrs: ["0.0.0.0/0"],
action: "allow",
}],
});
const debian = civo.getDiskImage({
filters: [{
key: "name",
values: ["debian-10"],
}],
});
// Create a new instance
const exampleInstance = new civo.Instance("example", {
hostname: "example",
notes: "This is an example instance",
firewallId: exampleVpcFirewall.vpcFirewallId,
networkId: example.vpcNetworkId,
size: "g3.xsmall",
diskImage: debian.then(debian => debian.diskimages?.[0]?.id),
});
import pulumi
import pulumi_civo as civo
example = civo.VpcNetwork("example", label="example-network")
example_vpc_firewall = civo.VpcFirewall("example",
name="example-firewall",
network_id=example.vpc_network_id,
create_default_rules=False,
ingress_rules=[
{
"label": "http",
"protocol": "tcp",
"port_range": "80",
"cidrs": ["0.0.0.0"],
"action": "allow",
},
{
"label": "https",
"protocol": "tcp",
"port_range": "443",
"cidrs": ["0.0.0.0"],
"action": "allow",
},
{
"label": "ssh",
"protocol": "tcp",
"port_range": "22",
"cidrs": [
"192.168.1.1/32",
"192.168.10.4/32",
"192.168.10.10/32",
],
"action": "allow",
},
],
egress_rules=[{
"label": "all",
"protocol": "tcp",
"port_range": "1-65535",
"cidrs": ["0.0.0.0/0"],
"action": "allow",
}])
debian = civo.get_disk_image(filters=[{
"key": "name",
"values": ["debian-10"],
}])
# Create a new instance
example_instance = civo.Instance("example",
hostname="example",
notes="This is an example instance",
firewall_id=example_vpc_firewall.vpc_firewall_id,
network_id=example.vpc_network_id,
size="g3.xsmall",
disk_image=debian.diskimages[0].id)
package main
import (
"github.com/pulumi/pulumi-terraform-provider/sdks/go/civo/civo"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
example, err := civo.NewVpcNetwork(ctx, "example", &civo.VpcNetworkArgs{
Label: pulumi.String("example-network"),
})
if err != nil {
return err
}
exampleVpcFirewall, err := civo.NewVpcFirewall(ctx, "example", &civo.VpcFirewallArgs{
Name: pulumi.String("example-firewall"),
NetworkId: example.VpcNetworkId,
CreateDefaultRules: pulumi.Bool(false),
IngressRules: civo.VpcFirewallIngressRuleArray{
&civo.VpcFirewallIngressRuleArgs{
Label: pulumi.String("http"),
Protocol: pulumi.String("tcp"),
PortRange: pulumi.String("80"),
Cidrs: pulumi.StringArray{
pulumi.String("0.0.0.0"),
},
Action: pulumi.String("allow"),
},
&civo.VpcFirewallIngressRuleArgs{
Label: pulumi.String("https"),
Protocol: pulumi.String("tcp"),
PortRange: pulumi.String("443"),
Cidrs: pulumi.StringArray{
pulumi.String("0.0.0.0"),
},
Action: pulumi.String("allow"),
},
&civo.VpcFirewallIngressRuleArgs{
Label: pulumi.String("ssh"),
Protocol: pulumi.String("tcp"),
PortRange: pulumi.String("22"),
Cidrs: pulumi.StringArray{
pulumi.String("192.168.1.1/32"),
pulumi.String("192.168.10.4/32"),
pulumi.String("192.168.10.10/32"),
},
Action: pulumi.String("allow"),
},
},
EgressRules: civo.VpcFirewallEgressRuleArray{
&civo.VpcFirewallEgressRuleArgs{
Label: pulumi.String("all"),
Protocol: pulumi.String("tcp"),
PortRange: pulumi.String("1-65535"),
Cidrs: pulumi.StringArray{
pulumi.String("0.0.0.0/0"),
},
Action: pulumi.String("allow"),
},
},
})
if err != nil {
return err
}
debian, err := civo.GetDiskImage(ctx, &civo.GetDiskImageArgs{
Filters: []civo.GetDiskImageFilter{
{
Key: "name",
Values: []string{
"debian-10",
},
},
},
}, nil)
if err != nil {
return err
}
// Create a new instance
_, err = civo.NewInstance(ctx, "example", &civo.InstanceArgs{
Hostname: pulumi.String("example"),
Notes: pulumi.String("This is an example instance"),
FirewallId: exampleVpcFirewall.VpcFirewallId,
NetworkId: example.VpcNetworkId,
Size: pulumi.String("g3.xsmall"),
DiskImage: pulumi.String(debian.Diskimages[0].Id),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Civo = Pulumi.Civo;
return await Deployment.RunAsync(() =>
{
var example = new Civo.VpcNetwork("example", new()
{
Label = "example-network",
});
var exampleVpcFirewall = new Civo.VpcFirewall("example", new()
{
Name = "example-firewall",
NetworkId = example.VpcNetworkId,
CreateDefaultRules = false,
IngressRules = new[]
{
new Civo.Inputs.VpcFirewallIngressRuleArgs
{
Label = "http",
Protocol = "tcp",
PortRange = "80",
Cidrs = new[]
{
"0.0.0.0",
},
Action = "allow",
},
new Civo.Inputs.VpcFirewallIngressRuleArgs
{
Label = "https",
Protocol = "tcp",
PortRange = "443",
Cidrs = new[]
{
"0.0.0.0",
},
Action = "allow",
},
new Civo.Inputs.VpcFirewallIngressRuleArgs
{
Label = "ssh",
Protocol = "tcp",
PortRange = "22",
Cidrs = new[]
{
"192.168.1.1/32",
"192.168.10.4/32",
"192.168.10.10/32",
},
Action = "allow",
},
},
EgressRules = new[]
{
new Civo.Inputs.VpcFirewallEgressRuleArgs
{
Label = "all",
Protocol = "tcp",
PortRange = "1-65535",
Cidrs = new[]
{
"0.0.0.0/0",
},
Action = "allow",
},
},
});
var debian = Civo.GetDiskImage.Invoke(new()
{
Filters = new[]
{
new Civo.Inputs.GetDiskImageFilterInputArgs
{
Key = "name",
Values = new[]
{
"debian-10",
},
},
},
});
// Create a new instance
var exampleInstance = new Civo.Instance("example", new()
{
Hostname = "example",
Notes = "This is an example instance",
FirewallId = exampleVpcFirewall.VpcFirewallId,
NetworkId = example.VpcNetworkId,
Size = "g3.xsmall",
DiskImage = debian.Apply(getDiskImageResult => getDiskImageResult.Diskimages[0]?.Id),
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.civo.VpcNetwork;
import com.pulumi.civo.VpcNetworkArgs;
import com.pulumi.civo.VpcFirewall;
import com.pulumi.civo.VpcFirewallArgs;
import com.pulumi.civo.inputs.VpcFirewallIngressRuleArgs;
import com.pulumi.civo.inputs.VpcFirewallEgressRuleArgs;
import com.pulumi.civo.CivoFunctions;
import com.pulumi.civo.inputs.GetDiskImageArgs;
import com.pulumi.civo.Instance;
import com.pulumi.civo.InstanceArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var example = new VpcNetwork("example", VpcNetworkArgs.builder()
.label("example-network")
.build());
var exampleVpcFirewall = new VpcFirewall("exampleVpcFirewall", VpcFirewallArgs.builder()
.name("example-firewall")
.networkId(example.vpcNetworkId())
.createDefaultRules(false)
.ingressRules(
VpcFirewallIngressRuleArgs.builder()
.label("http")
.protocol("tcp")
.portRange("80")
.cidrs("0.0.0.0")
.action("allow")
.build(),
VpcFirewallIngressRuleArgs.builder()
.label("https")
.protocol("tcp")
.portRange("443")
.cidrs("0.0.0.0")
.action("allow")
.build(),
VpcFirewallIngressRuleArgs.builder()
.label("ssh")
.protocol("tcp")
.portRange("22")
.cidrs(
"192.168.1.1/32",
"192.168.10.4/32",
"192.168.10.10/32")
.action("allow")
.build())
.egressRules(VpcFirewallEgressRuleArgs.builder()
.label("all")
.protocol("tcp")
.portRange("1-65535")
.cidrs("0.0.0.0/0")
.action("allow")
.build())
.build());
final var debian = CivoFunctions.getDiskImage(GetDiskImageArgs.builder()
.filters(GetDiskImageFilterArgs.builder()
.key("name")
.values("debian-10")
.build())
.build());
// Create a new instance
var exampleInstance = new Instance("exampleInstance", InstanceArgs.builder()
.hostname("example")
.notes("This is an example instance")
.firewallId(exampleVpcFirewall.vpcFirewallId())
.networkId(example.vpcNetworkId())
.size("g3.xsmall")
.diskImage(debian.diskimages()[0].id())
.build());
}
}
resources:
example:
type: civo:VpcNetwork
properties:
label: example-network
exampleVpcFirewall:
type: civo:VpcFirewall
name: example
properties:
name: example-firewall
networkId: ${example.vpcNetworkId}
createDefaultRules: false # Needs to be false when declaring custom rules at creation time.
ingressRules:
- label: http
protocol: tcp
portRange: '80'
cidrs:
- 0.0.0.0
action: allow
- label: https
protocol: tcp
portRange: '443'
cidrs:
- 0.0.0.0
action: allow
- label: ssh
protocol: tcp
portRange: '22'
cidrs:
- 192.168.1.1/32
- 192.168.10.4/32
- 192.168.10.10/32
action: allow
egressRules:
- label: all
protocol: tcp
portRange: 1-65535
cidrs:
- 0.0.0.0/0
action: allow
# Create a new instance
exampleInstance:
type: civo:Instance
name: example
properties:
hostname: example
notes: This is an example instance
firewallId: ${exampleVpcFirewall.vpcFirewallId}
networkId: ${example.vpcNetworkId}
size: g3.xsmall
diskImage: ${debian.diskimages[0].id}
variables:
debian:
fn::invoke:
function: civo:getDiskImage
arguments:
filters:
- key: name
values:
- debian-10
Example coming soon!
Simple firewall
This the minimum amount of code to create a firewall with default rules:
import * as pulumi from "@pulumi/pulumi";
import * as civo from "@pulumi/civo";
// ...
const example = new civo.VpcFirewall("example", {
name: "example-firewall",
networkId: exampleCivoVpcNetwork.id,
});
import pulumi
import pulumi_civo as civo
# ...
example = civo.VpcFirewall("example",
name="example-firewall",
network_id=example_civo_vpc_network["id"])
package main
import (
"github.com/pulumi/pulumi-terraform-provider/sdks/go/civo/civo"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
// ...
_, err := civo.NewVpcFirewall(ctx, "example", &civo.VpcFirewallArgs{
Name: pulumi.String("example-firewall"),
NetworkId: pulumi.Any(exampleCivoVpcNetwork.Id),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Civo = Pulumi.Civo;
return await Deployment.RunAsync(() =>
{
// ...
var example = new Civo.VpcFirewall("example", new()
{
Name = "example-firewall",
NetworkId = exampleCivoVpcNetwork.Id,
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.civo.VpcFirewall;
import com.pulumi.civo.VpcFirewallArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
// ...
var example = new VpcFirewall("example", VpcFirewallArgs.builder()
.name("example-firewall")
.networkId(exampleCivoVpcNetwork.id())
.build());
}
}
resources:
# ...
example:
type: civo:VpcFirewall
properties:
name: example-firewall
networkId: ${exampleCivoVpcNetwork.id}
Example coming soon!
Create VpcFirewall Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new VpcFirewall(name: string, args?: VpcFirewallArgs, opts?: CustomResourceOptions);@overload
def VpcFirewall(resource_name: str,
args: Optional[VpcFirewallArgs] = None,
opts: Optional[ResourceOptions] = None)
@overload
def VpcFirewall(resource_name: str,
opts: Optional[ResourceOptions] = None,
create_default_rules: Optional[bool] = None,
egress_rules: Optional[Sequence[VpcFirewallEgressRuleArgs]] = None,
ingress_rules: Optional[Sequence[VpcFirewallIngressRuleArgs]] = None,
name: Optional[str] = None,
network_id: Optional[str] = None,
region: Optional[str] = None,
timeouts: Optional[VpcFirewallTimeoutsArgs] = None,
vpc_firewall_id: Optional[str] = None)func NewVpcFirewall(ctx *Context, name string, args *VpcFirewallArgs, opts ...ResourceOption) (*VpcFirewall, error)public VpcFirewall(string name, VpcFirewallArgs? args = null, CustomResourceOptions? opts = null)
public VpcFirewall(String name, VpcFirewallArgs args)
public VpcFirewall(String name, VpcFirewallArgs args, CustomResourceOptions options)
type: civo:VpcFirewall
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "civo_vpc_firewall" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args VpcFirewallArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args VpcFirewallArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args VpcFirewallArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args VpcFirewallArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args VpcFirewallArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var vpcFirewallResource = new Civo.VpcFirewall("vpcFirewallResource", new()
{
CreateDefaultRules = false,
EgressRules = new[]
{
new Civo.Inputs.VpcFirewallEgressRuleArgs
{
Action = "string",
Cidrs = new[]
{
"string",
},
Id = "string",
Label = "string",
PortRange = "string",
Protocol = "string",
},
},
IngressRules = new[]
{
new Civo.Inputs.VpcFirewallIngressRuleArgs
{
Action = "string",
Cidrs = new[]
{
"string",
},
Id = "string",
Label = "string",
PortRange = "string",
Protocol = "string",
},
},
Name = "string",
NetworkId = "string",
Region = "string",
Timeouts = new Civo.Inputs.VpcFirewallTimeoutsArgs
{
Create = "string",
Delete = "string",
Update = "string",
},
VpcFirewallId = "string",
});
example, err := civo.NewVpcFirewall(ctx, "vpcFirewallResource", &civo.VpcFirewallArgs{
CreateDefaultRules: pulumi.Bool(false),
EgressRules: civo.VpcFirewallEgressRuleArray{
&civo.VpcFirewallEgressRuleArgs{
Action: pulumi.String("string"),
Cidrs: pulumi.StringArray{
pulumi.String("string"),
},
Id: pulumi.String("string"),
Label: pulumi.String("string"),
PortRange: pulumi.String("string"),
Protocol: pulumi.String("string"),
},
},
IngressRules: civo.VpcFirewallIngressRuleArray{
&civo.VpcFirewallIngressRuleArgs{
Action: pulumi.String("string"),
Cidrs: pulumi.StringArray{
pulumi.String("string"),
},
Id: pulumi.String("string"),
Label: pulumi.String("string"),
PortRange: pulumi.String("string"),
Protocol: pulumi.String("string"),
},
},
Name: pulumi.String("string"),
NetworkId: pulumi.String("string"),
Region: pulumi.String("string"),
Timeouts: &civo.VpcFirewallTimeoutsArgs{
Create: pulumi.String("string"),
Delete: pulumi.String("string"),
Update: pulumi.String("string"),
},
VpcFirewallId: pulumi.String("string"),
})
resource "civo_vpc_firewall" "vpcFirewallResource" {
lifecycle {
create_before_destroy = true
}
create_default_rules = false
egress_rules {
action = "string"
cidrs = ["string"]
id = "string"
label = "string"
port_range = "string"
protocol = "string"
}
ingress_rules {
action = "string"
cidrs = ["string"]
id = "string"
label = "string"
port_range = "string"
protocol = "string"
}
name = "string"
network_id = "string"
region = "string"
timeouts = {
create = "string"
delete = "string"
update = "string"
}
vpc_firewall_id = "string"
}
var vpcFirewallResource = new VpcFirewall("vpcFirewallResource", VpcFirewallArgs.builder()
.createDefaultRules(false)
.egressRules(VpcFirewallEgressRuleArgs.builder()
.action("string")
.cidrs("string")
.id("string")
.label("string")
.portRange("string")
.protocol("string")
.build())
.ingressRules(VpcFirewallIngressRuleArgs.builder()
.action("string")
.cidrs("string")
.id("string")
.label("string")
.portRange("string")
.protocol("string")
.build())
.name("string")
.networkId("string")
.region("string")
.timeouts(VpcFirewallTimeoutsArgs.builder()
.create("string")
.delete("string")
.update("string")
.build())
.vpcFirewallId("string")
.build());
vpc_firewall_resource = civo.VpcFirewall("vpcFirewallResource",
create_default_rules=False,
egress_rules=[{
"action": "string",
"cidrs": ["string"],
"id": "string",
"label": "string",
"port_range": "string",
"protocol": "string",
}],
ingress_rules=[{
"action": "string",
"cidrs": ["string"],
"id": "string",
"label": "string",
"port_range": "string",
"protocol": "string",
}],
name="string",
network_id="string",
region="string",
timeouts={
"create": "string",
"delete": "string",
"update": "string",
},
vpc_firewall_id="string")
const vpcFirewallResource = new civo.VpcFirewall("vpcFirewallResource", {
createDefaultRules: false,
egressRules: [{
action: "string",
cidrs: ["string"],
id: "string",
label: "string",
portRange: "string",
protocol: "string",
}],
ingressRules: [{
action: "string",
cidrs: ["string"],
id: "string",
label: "string",
portRange: "string",
protocol: "string",
}],
name: "string",
networkId: "string",
region: "string",
timeouts: {
create: "string",
"delete": "string",
update: "string",
},
vpcFirewallId: "string",
});
type: civo:VpcFirewall
properties:
createDefaultRules: false
egressRules:
- action: string
cidrs:
- string
id: string
label: string
portRange: string
protocol: string
ingressRules:
- action: string
cidrs:
- string
id: string
label: string
portRange: string
protocol: string
name: string
networkId: string
region: string
timeouts:
create: string
delete: string
update: string
vpcFirewallId: string
VpcFirewall Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The VpcFirewall resource accepts the following input properties:
- Create
Default boolRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- Egress
Rules List<VpcFirewall Egress Rule> - The egress rules, this is a list of rules that will be applied to the firewall
- Ingress
Rules List<VpcFirewall Ingress Rule> - The ingress rules, this is a list of rules that will be applied to the firewall
- Name string
- The firewall name
- Network
Id string - The firewall network, if is not defined we use the default network
- Region string
- The firewall region, if is not defined we use the global defined in the provider
- Timeouts
Vpc
Firewall Timeouts - Vpc
Firewall stringId - The ID of this resource.
- Create
Default boolRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- Egress
Rules []VpcFirewall Egress Rule Args - The egress rules, this is a list of rules that will be applied to the firewall
- Ingress
Rules []VpcFirewall Ingress Rule Args - The ingress rules, this is a list of rules that will be applied to the firewall
- Name string
- The firewall name
- Network
Id string - The firewall network, if is not defined we use the default network
- Region string
- The firewall region, if is not defined we use the global defined in the provider
- Timeouts
Vpc
Firewall Timeouts Args - Vpc
Firewall stringId - The ID of this resource.
- create_
default_ boolrules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress_
rules list(object) - The egress rules, this is a list of rules that will be applied to the firewall
- ingress_
rules list(object) - The ingress rules, this is a list of rules that will be applied to the firewall
- name string
- The firewall name
- network_
id string - The firewall network, if is not defined we use the default network
- region string
- The firewall region, if is not defined we use the global defined in the provider
- timeouts object
- vpc_
firewall_ stringid - The ID of this resource.
- create
Default BooleanRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress
Rules List<VpcFirewall Egress Rule> - The egress rules, this is a list of rules that will be applied to the firewall
- ingress
Rules List<VpcFirewall Ingress Rule> - The ingress rules, this is a list of rules that will be applied to the firewall
- name String
- The firewall name
- network
Id String - The firewall network, if is not defined we use the default network
- region String
- The firewall region, if is not defined we use the global defined in the provider
- timeouts
Vpc
Firewall Timeouts - vpc
Firewall StringId - The ID of this resource.
- create
Default booleanRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress
Rules VpcFirewall Egress Rule[] - The egress rules, this is a list of rules that will be applied to the firewall
- ingress
Rules VpcFirewall Ingress Rule[] - The ingress rules, this is a list of rules that will be applied to the firewall
- name string
- The firewall name
- network
Id string - The firewall network, if is not defined we use the default network
- region string
- The firewall region, if is not defined we use the global defined in the provider
- timeouts
Vpc
Firewall Timeouts - vpc
Firewall stringId - The ID of this resource.
- create_
default_ boolrules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress_
rules Sequence[VpcFirewall Egress Rule Args] - The egress rules, this is a list of rules that will be applied to the firewall
- ingress_
rules Sequence[VpcFirewall Ingress Rule Args] - The ingress rules, this is a list of rules that will be applied to the firewall
- name str
- The firewall name
- network_
id str - The firewall network, if is not defined we use the default network
- region str
- The firewall region, if is not defined we use the global defined in the provider
- timeouts
Vpc
Firewall Timeouts Args - vpc_
firewall_ strid - The ID of this resource.
- create
Default BooleanRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress
Rules List<Property Map> - The egress rules, this is a list of rules that will be applied to the firewall
- ingress
Rules List<Property Map> - The ingress rules, this is a list of rules that will be applied to the firewall
- name String
- The firewall name
- network
Id String - The firewall network, if is not defined we use the default network
- region String
- The firewall region, if is not defined we use the global defined in the provider
- timeouts Property Map
- vpc
Firewall StringId - The ID of this resource.
Outputs
All input properties are implicitly available as output properties. Additionally, the VpcFirewall resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing VpcFirewall Resource
Get an existing VpcFirewall resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: VpcFirewallState, opts?: CustomResourceOptions): VpcFirewall@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
create_default_rules: Optional[bool] = None,
egress_rules: Optional[Sequence[VpcFirewallEgressRuleArgs]] = None,
ingress_rules: Optional[Sequence[VpcFirewallIngressRuleArgs]] = None,
name: Optional[str] = None,
network_id: Optional[str] = None,
region: Optional[str] = None,
timeouts: Optional[VpcFirewallTimeoutsArgs] = None,
vpc_firewall_id: Optional[str] = None) -> VpcFirewallfunc GetVpcFirewall(ctx *Context, name string, id IDInput, state *VpcFirewallState, opts ...ResourceOption) (*VpcFirewall, error)public static VpcFirewall Get(string name, Input<string> id, VpcFirewallState? state, CustomResourceOptions? opts = null)public static VpcFirewall get(String name, Output<String> id, VpcFirewallState state, CustomResourceOptions options)resources: _: type: civo:VpcFirewall get: id: ${id}import {
to = civo_vpc_firewall.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Create
Default boolRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- Egress
Rules List<VpcFirewall Egress Rule> - The egress rules, this is a list of rules that will be applied to the firewall
- Ingress
Rules List<VpcFirewall Ingress Rule> - The ingress rules, this is a list of rules that will be applied to the firewall
- Name string
- The firewall name
- Network
Id string - The firewall network, if is not defined we use the default network
- Region string
- The firewall region, if is not defined we use the global defined in the provider
- Timeouts
Vpc
Firewall Timeouts - Vpc
Firewall stringId - The ID of this resource.
- Create
Default boolRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- Egress
Rules []VpcFirewall Egress Rule Args - The egress rules, this is a list of rules that will be applied to the firewall
- Ingress
Rules []VpcFirewall Ingress Rule Args - The ingress rules, this is a list of rules that will be applied to the firewall
- Name string
- The firewall name
- Network
Id string - The firewall network, if is not defined we use the default network
- Region string
- The firewall region, if is not defined we use the global defined in the provider
- Timeouts
Vpc
Firewall Timeouts Args - Vpc
Firewall stringId - The ID of this resource.
- create_
default_ boolrules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress_
rules list(object) - The egress rules, this is a list of rules that will be applied to the firewall
- ingress_
rules list(object) - The ingress rules, this is a list of rules that will be applied to the firewall
- name string
- The firewall name
- network_
id string - The firewall network, if is not defined we use the default network
- region string
- The firewall region, if is not defined we use the global defined in the provider
- timeouts object
- vpc_
firewall_ stringid - The ID of this resource.
- create
Default BooleanRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress
Rules List<VpcFirewall Egress Rule> - The egress rules, this is a list of rules that will be applied to the firewall
- ingress
Rules List<VpcFirewall Ingress Rule> - The ingress rules, this is a list of rules that will be applied to the firewall
- name String
- The firewall name
- network
Id String - The firewall network, if is not defined we use the default network
- region String
- The firewall region, if is not defined we use the global defined in the provider
- timeouts
Vpc
Firewall Timeouts - vpc
Firewall StringId - The ID of this resource.
- create
Default booleanRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress
Rules VpcFirewall Egress Rule[] - The egress rules, this is a list of rules that will be applied to the firewall
- ingress
Rules VpcFirewall Ingress Rule[] - The ingress rules, this is a list of rules that will be applied to the firewall
- name string
- The firewall name
- network
Id string - The firewall network, if is not defined we use the default network
- region string
- The firewall region, if is not defined we use the global defined in the provider
- timeouts
Vpc
Firewall Timeouts - vpc
Firewall stringId - The ID of this resource.
- create_
default_ boolrules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress_
rules Sequence[VpcFirewall Egress Rule Args] - The egress rules, this is a list of rules that will be applied to the firewall
- ingress_
rules Sequence[VpcFirewall Ingress Rule Args] - The ingress rules, this is a list of rules that will be applied to the firewall
- name str
- The firewall name
- network_
id str - The firewall network, if is not defined we use the default network
- region str
- The firewall region, if is not defined we use the global defined in the provider
- timeouts
Vpc
Firewall Timeouts Args - vpc_
firewall_ strid - The ID of this resource.
- create
Default BooleanRules - The create rules flag is used to create the default firewall rules, if is not defined will be set to true. This flag only takes effect when the firewall is created; changing it on an existing firewall never recreates the firewall and does not re-create the default rules. If you set it to false you need to define at least one ingress or egress rule
- egress
Rules List<Property Map> - The egress rules, this is a list of rules that will be applied to the firewall
- ingress
Rules List<Property Map> - The ingress rules, this is a list of rules that will be applied to the firewall
- name String
- The firewall name
- network
Id String - The firewall network, if is not defined we use the default network
- region String
- The firewall region, if is not defined we use the global defined in the provider
- timeouts Property Map
- vpc
Firewall StringId - The ID of this resource.
Supporting Types
VpcFirewallEgressRule, VpcFirewallEgressRuleArgs
- Action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - Cidrs List<string>
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- Id string
- Label string
- A string that will be the displayed name/reference for this rule
- Port
Range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - Protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- Action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - Cidrs []string
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- Id string
- Label string
- A string that will be the displayed name/reference for this rule
- Port
Range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - Protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs list(string)
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id string
- label string
- A string that will be the displayed name/reference for this rule
- port_
range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action String
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs List<String>
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id String
- label String
- A string that will be the displayed name/reference for this rule
- port
Range String - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol String
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs string[]
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id string
- label string
- A string that will be the displayed name/reference for this rule
- port
Range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action str
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs Sequence[str]
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id str
- label str
- A string that will be the displayed name/reference for this rule
- port_
range str - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol str
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action String
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs List<String>
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id String
- label String
- A string that will be the displayed name/reference for this rule
- port
Range String - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol String
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
VpcFirewallIngressRule, VpcFirewallIngressRuleArgs
- Action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - Cidrs List<string>
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- Id string
- Label string
- A string that will be the displayed name/reference for this rule
- Port
Range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - Protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- Action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - Cidrs []string
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- Id string
- Label string
- A string that will be the displayed name/reference for this rule
- Port
Range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - Protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs list(string)
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id string
- label string
- A string that will be the displayed name/reference for this rule
- port_
range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action String
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs List<String>
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id String
- label String
- A string that will be the displayed name/reference for this rule
- port
Range String - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol String
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action string
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs string[]
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id string
- label string
- A string that will be the displayed name/reference for this rule
- port
Range string - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol string
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action str
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs Sequence[str]
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id str
- label str
- A string that will be the displayed name/reference for this rule
- port_
range str - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol str
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
- action String
- The action of the rule can be allow or deny. When we set the
action = 'allow', this is going to add a rule to allow traffic. Similarly, settingaction = 'deny'will deny the traffic. - cidrs List<String>
- The CIDR notation of the other end to affect, or a valid network CIDR (e.g. 0.0.0.0/0 to open for everyone or 1.2.3.4/32 to open just for a specific IP address)
- id String
- label String
- A string that will be the displayed name/reference for this rule
- port
Range String - The port or port range to open, can be a single port or a range separated by a dash (
-), e.g.80or80-443 - protocol String
- The protocol choice from
tcp,udporicmp(the default if unspecified istcp)
VpcFirewallTimeouts, VpcFirewallTimeoutsArgs
Import
using ID
$ pulumi import civo:index/vpcFirewall:VpcFirewall www b8ecd2ab-2267-4a5e-8692-cbf1d32583e3
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- Civo civo/terraform-provider-civo
- License
- Notes
- This Pulumi package is based on the
civoTerraform Provider.
published on Tuesday, Sep 29, 2026 by civo