published on Tuesday, Sep 15, 2026 by imperva
published on Tuesday, Sep 15, 2026 by imperva
Provides an Imperva AI Application Security application resource.
An AI Application Security application represents a protected AI/LLM endpoint. The deployment
type (application_type) determines how traffic reaches the application:
SDK- traffic is inspected via the Inline Reverse Proxy integrated into your application.API- traffic is inspected via the AI Application Security API.EDGE- traffic is inspected inline at the edge. This type requires aconfigurationblock describing how to extract prompts and responses.
Example Usage
SDK Application
import * as pulumi from "@pulumi/pulumi";
import * as incapsula from "@pulumi/incapsula";
const sdkApp = new incapsula.AiApplicationSecurityApplication("sdk_app", {
accountId: 1234567,
name: "my-sdk-app",
applicationType: "SDK",
region: "US",
});
import pulumi
import pulumi_incapsula as incapsula
sdk_app = incapsula.AiApplicationSecurityApplication("sdk_app",
account_id=1234567,
name="my-sdk-app",
application_type="SDK",
region="US")
package main
import (
"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := incapsula.NewAiApplicationSecurityApplication(ctx, "sdk_app", &incapsula.AiApplicationSecurityApplicationArgs{
AccountId: pulumi.Float64(1234567),
Name: pulumi.String("my-sdk-app"),
ApplicationType: pulumi.String("SDK"),
Region: pulumi.String("US"),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Incapsula = Pulumi.Incapsula;
return await Deployment.RunAsync(() =>
{
var sdkApp = new Incapsula.AiApplicationSecurityApplication("sdk_app", new()
{
AccountId = 1234567,
Name = "my-sdk-app",
ApplicationType = "SDK",
Region = "US",
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.incapsula.AiApplicationSecurityApplication;
import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var sdkApp = new AiApplicationSecurityApplication("sdkApp", AiApplicationSecurityApplicationArgs.builder()
.accountId(1234567.0)
.name("my-sdk-app")
.applicationType("SDK")
.region("US")
.build());
}
}
resources:
sdkApp:
type: incapsula:AiApplicationSecurityApplication
name: sdk_app
properties:
accountId: 1.234567e+06
name: my-sdk-app
applicationType: SDK
region: US
Example coming soon!
API Application
import * as pulumi from "@pulumi/pulumi";
import * as incapsula from "@pulumi/incapsula";
const apiApp = new incapsula.AiApplicationSecurityApplication("api_app", {
accountId: 1234567,
name: "my-api-app",
applicationType: "API",
region: "EU",
});
import pulumi
import pulumi_incapsula as incapsula
api_app = incapsula.AiApplicationSecurityApplication("api_app",
account_id=1234567,
name="my-api-app",
application_type="API",
region="EU")
package main
import (
"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := incapsula.NewAiApplicationSecurityApplication(ctx, "api_app", &incapsula.AiApplicationSecurityApplicationArgs{
AccountId: pulumi.Float64(1234567),
Name: pulumi.String("my-api-app"),
ApplicationType: pulumi.String("API"),
Region: pulumi.String("EU"),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Incapsula = Pulumi.Incapsula;
return await Deployment.RunAsync(() =>
{
var apiApp = new Incapsula.AiApplicationSecurityApplication("api_app", new()
{
AccountId = 1234567,
Name = "my-api-app",
ApplicationType = "API",
Region = "EU",
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.incapsula.AiApplicationSecurityApplication;
import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var apiApp = new AiApplicationSecurityApplication("apiApp", AiApplicationSecurityApplicationArgs.builder()
.accountId(1234567.0)
.name("my-api-app")
.applicationType("API")
.region("EU")
.build());
}
}
resources:
apiApp:
type: incapsula:AiApplicationSecurityApplication
name: api_app
properties:
accountId: 1.234567e+06
name: my-api-app
applicationType: API
region: EU
Example coming soon!
EDGE Application
An EDGE application requires a configuration block:
import * as pulumi from "@pulumi/pulumi";
import * as incapsula from "@pulumi/incapsula";
const edgeApp = new incapsula.AiApplicationSecurityApplication("edge_app", {
accountId: 1234567,
name: "my-edge-app",
applicationType: "EDGE",
region: "US",
configuration: {
siteId: 987654,
path: "/v1/chat/completions",
contentType: "application/json",
promptLocation: "$.body",
blockedResponseStructure: JSON.stringify({
error: "$BLOCKED_MESSAGE",
}),
isStreaming: false,
request: {
messagePath: "$.messages",
contentPath: "$.content",
rolePath: "$.role",
},
response: {
rolePath: "$.choices.0.message.role",
contentPath: "$.choices.0.message.content",
finishReasonPath: "$.choices.0.finish_reason",
finishReasonValue: "$.stop",
endOfStreamMarker: "[DONE]",
},
},
});
import pulumi
import json
import pulumi_incapsula as incapsula
edge_app = incapsula.AiApplicationSecurityApplication("edge_app",
account_id=1234567,
name="my-edge-app",
application_type="EDGE",
region="US",
configuration={
"site_id": 987654,
"path": "/v1/chat/completions",
"content_type": "application/json",
"prompt_location": "$.body",
"blocked_response_structure": json.dumps({
"error": "$BLOCKED_MESSAGE",
}),
"is_streaming": False,
"request": {
"message_path": "$.messages",
"content_path": "$.content",
"role_path": "$.role",
},
"response": {
"role_path": "$.choices.0.message.role",
"content_path": "$.choices.0.message.content",
"finish_reason_path": "$.choices.0.finish_reason",
"finish_reason_value": "$.stop",
"end_of_stream_marker": "[DONE]",
},
})
package main
import (
"encoding/json"
"github.com/pulumi/pulumi-terraform-provider/sdks/go/incapsula/v3/incapsula"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
tmpJSON0, err := json.Marshal(map[string]interface{}{
"error": "$BLOCKED_MESSAGE",
})
if err != nil {
return err
}
json0 := string(tmpJSON0)
_, err = incapsula.NewAiApplicationSecurityApplication(ctx, "edge_app", &incapsula.AiApplicationSecurityApplicationArgs{
AccountId: pulumi.Float64(1234567),
Name: pulumi.String("my-edge-app"),
ApplicationType: pulumi.String("EDGE"),
Region: pulumi.String("US"),
Configuration: &incapsula.AiApplicationSecurityApplicationConfigurationArgs{
SiteId: pulumi.Float64(987654),
Path: pulumi.String("/v1/chat/completions"),
ContentType: pulumi.String("application/json"),
PromptLocation: pulumi.String("$.body"),
BlockedResponseStructure: pulumi.String(json0),
IsStreaming: pulumi.Bool(false),
Request: &incapsula.AiApplicationSecurityApplicationConfigurationRequestArgs{
MessagePath: pulumi.String("$.messages"),
ContentPath: pulumi.String("$.content"),
RolePath: pulumi.String("$.role"),
},
Response: &incapsula.AiApplicationSecurityApplicationConfigurationResponseArgs{
RolePath: pulumi.String("$.choices.0.message.role"),
ContentPath: pulumi.String("$.choices.0.message.content"),
FinishReasonPath: pulumi.String("$.choices.0.finish_reason"),
FinishReasonValue: pulumi.String("$.stop"),
EndOfStreamMarker: pulumi.String("[DONE]"),
},
},
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using System.Text.Json;
using Pulumi;
using Incapsula = Pulumi.Incapsula;
return await Deployment.RunAsync(() =>
{
var edgeApp = new Incapsula.AiApplicationSecurityApplication("edge_app", new()
{
AccountId = 1234567,
Name = "my-edge-app",
ApplicationType = "EDGE",
Region = "US",
Configuration = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationArgs
{
SiteId = 987654,
Path = "/v1/chat/completions",
ContentType = "application/json",
PromptLocation = "$.body",
BlockedResponseStructure = JsonSerializer.Serialize(new Dictionary<string, object?>
{
["error"] = "$BLOCKED_MESSAGE",
}),
IsStreaming = false,
Request = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationRequestArgs
{
MessagePath = "$.messages",
ContentPath = "$.content",
RolePath = "$.role",
},
Response = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationResponseArgs
{
RolePath = "$.choices.0.message.role",
ContentPath = "$.choices.0.message.content",
FinishReasonPath = "$.choices.0.finish_reason",
FinishReasonValue = "$.stop",
EndOfStreamMarker = "[DONE]",
},
},
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.incapsula.AiApplicationSecurityApplication;
import com.pulumi.incapsula.AiApplicationSecurityApplicationArgs;
import com.pulumi.incapsula.inputs.AiApplicationSecurityApplicationConfigurationArgs;
import com.pulumi.incapsula.inputs.AiApplicationSecurityApplicationConfigurationRequestArgs;
import com.pulumi.incapsula.inputs.AiApplicationSecurityApplicationConfigurationResponseArgs;
import static com.pulumi.codegen.internal.Serialization.*;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var edgeApp = new AiApplicationSecurityApplication("edgeApp", AiApplicationSecurityApplicationArgs.builder()
.accountId(1234567.0)
.name("my-edge-app")
.applicationType("EDGE")
.region("US")
.configuration(AiApplicationSecurityApplicationConfigurationArgs.builder()
.siteId(987654.0)
.path("/v1/chat/completions")
.contentType("application/json")
.promptLocation("$.body")
.blockedResponseStructure(serializeJson(
jsonObject(
jsonProperty("error", "$BLOCKED_MESSAGE")
)))
.isStreaming(false)
.request(AiApplicationSecurityApplicationConfigurationRequestArgs.builder()
.messagePath("$.messages")
.contentPath("$.content")
.rolePath("$.role")
.build())
.response(AiApplicationSecurityApplicationConfigurationResponseArgs.builder()
.rolePath("$.choices.0.message.role")
.contentPath("$.choices.0.message.content")
.finishReasonPath("$.choices.0.finish_reason")
.finishReasonValue("$.stop")
.endOfStreamMarker("[DONE]")
.build())
.build())
.build());
}
}
resources:
edgeApp:
type: incapsula:AiApplicationSecurityApplication
name: edge_app
properties:
accountId: 1.234567e+06
name: my-edge-app
applicationType: EDGE
region: US
configuration:
siteId: 987654
path: /v1/chat/completions
contentType: application/json
promptLocation: $.body
blockedResponseStructure:
fn::toJSON:
error: $BLOCKED_MESSAGE
isStreaming: false
request:
messagePath: $.messages
contentPath: $.content
rolePath: $.role
response:
rolePath: $.choices.0.message.role
contentPath: $.choices.0.message.content
finishReasonPath: $.choices.0.finish_reason
finishReasonValue: $.stop
endOfStreamMarker: '[DONE]'
Example coming soon!
JSONPath required. Every path field in the
configurationblock (prompt_location, and therequest/response*_pathfields) must be a valid JSONPath expression starting with$.blocked_response_structuremust contain the literal$BLOCKED_MESSAGEplaceholder, which the service replaces with the block reason at runtime.
Create AiApplicationSecurityApplication Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new AiApplicationSecurityApplication(name: string, args: AiApplicationSecurityApplicationArgs, opts?: CustomResourceOptions);@overload
def AiApplicationSecurityApplication(resource_name: str,
args: AiApplicationSecurityApplicationArgs,
opts: Optional[ResourceOptions] = None)
@overload
def AiApplicationSecurityApplication(resource_name: str,
opts: Optional[ResourceOptions] = None,
application_type: Optional[str] = None,
account_id: Optional[float] = None,
ai_application_security_application_id: Optional[str] = None,
configuration: Optional[AiApplicationSecurityApplicationConfigurationArgs] = None,
name: Optional[str] = None,
region: Optional[str] = None)func NewAiApplicationSecurityApplication(ctx *Context, name string, args AiApplicationSecurityApplicationArgs, opts ...ResourceOption) (*AiApplicationSecurityApplication, error)public AiApplicationSecurityApplication(string name, AiApplicationSecurityApplicationArgs args, CustomResourceOptions? opts = null)
public AiApplicationSecurityApplication(String name, AiApplicationSecurityApplicationArgs args)
public AiApplicationSecurityApplication(String name, AiApplicationSecurityApplicationArgs args, CustomResourceOptions options)
type: incapsula:AiApplicationSecurityApplication
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "incapsula_ai_application_security_application" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args AiApplicationSecurityApplicationArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args AiApplicationSecurityApplicationArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args AiApplicationSecurityApplicationArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args AiApplicationSecurityApplicationArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args AiApplicationSecurityApplicationArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var aiApplicationSecurityApplicationResource = new Incapsula.AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource", new()
{
ApplicationType = "string",
AccountId = 0.0,
AiApplicationSecurityApplicationId = "string",
Configuration = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationArgs
{
BlockedResponseStructure = "string",
ContentType = "string",
IsStreaming = false,
Path = "string",
PromptLocation = "string",
Request = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationRequestArgs
{
ContentPath = "string",
MessagePath = "string",
RolePath = "string",
},
Response = new Incapsula.Inputs.AiApplicationSecurityApplicationConfigurationResponseArgs
{
ContentPath = "string",
EndOfStreamMarker = "string",
FinishReasonPath = "string",
FinishReasonValue = "string",
RolePath = "string",
},
SiteId = 0.0,
},
Name = "string",
Region = "string",
});
example, err := incapsula.NewAiApplicationSecurityApplication(ctx, "aiApplicationSecurityApplicationResource", &incapsula.AiApplicationSecurityApplicationArgs{
ApplicationType: pulumi.String("string"),
AccountId: pulumi.Float64(0),
AiApplicationSecurityApplicationId: pulumi.String("string"),
Configuration: &incapsula.AiApplicationSecurityApplicationConfigurationArgs{
BlockedResponseStructure: pulumi.String("string"),
ContentType: pulumi.String("string"),
IsStreaming: pulumi.Bool(false),
Path: pulumi.String("string"),
PromptLocation: pulumi.String("string"),
Request: &incapsula.AiApplicationSecurityApplicationConfigurationRequestArgs{
ContentPath: pulumi.String("string"),
MessagePath: pulumi.String("string"),
RolePath: pulumi.String("string"),
},
Response: &incapsula.AiApplicationSecurityApplicationConfigurationResponseArgs{
ContentPath: pulumi.String("string"),
EndOfStreamMarker: pulumi.String("string"),
FinishReasonPath: pulumi.String("string"),
FinishReasonValue: pulumi.String("string"),
RolePath: pulumi.String("string"),
},
SiteId: pulumi.Float64(0),
},
Name: pulumi.String("string"),
Region: pulumi.String("string"),
})
resource "incapsula_ai_application_security_application" "aiApplicationSecurityApplicationResource" {
lifecycle {
create_before_destroy = true
}
application_type = "string"
account_id = 0
ai_application_security_application_id = "string"
configuration = {
blocked_response_structure = "string"
content_type = "string"
is_streaming = false
path = "string"
prompt_location = "string"
request = {
content_path = "string"
message_path = "string"
role_path = "string"
}
response = {
content_path = "string"
end_of_stream_marker = "string"
finish_reason_path = "string"
finish_reason_value = "string"
role_path = "string"
}
site_id = 0
}
name = "string"
region = "string"
}
var aiApplicationSecurityApplicationResource = new AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource", AiApplicationSecurityApplicationArgs.builder()
.applicationType("string")
.accountId(0.0)
.aiApplicationSecurityApplicationId("string")
.configuration(AiApplicationSecurityApplicationConfigurationArgs.builder()
.blockedResponseStructure("string")
.contentType("string")
.isStreaming(false)
.path("string")
.promptLocation("string")
.request(AiApplicationSecurityApplicationConfigurationRequestArgs.builder()
.contentPath("string")
.messagePath("string")
.rolePath("string")
.build())
.response(AiApplicationSecurityApplicationConfigurationResponseArgs.builder()
.contentPath("string")
.endOfStreamMarker("string")
.finishReasonPath("string")
.finishReasonValue("string")
.rolePath("string")
.build())
.siteId(0.0)
.build())
.name("string")
.region("string")
.build());
ai_application_security_application_resource = incapsula.AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource",
application_type="string",
account_id=float(0),
ai_application_security_application_id="string",
configuration={
"blocked_response_structure": "string",
"content_type": "string",
"is_streaming": False,
"path": "string",
"prompt_location": "string",
"request": {
"content_path": "string",
"message_path": "string",
"role_path": "string",
},
"response": {
"content_path": "string",
"end_of_stream_marker": "string",
"finish_reason_path": "string",
"finish_reason_value": "string",
"role_path": "string",
},
"site_id": float(0),
},
name="string",
region="string")
const aiApplicationSecurityApplicationResource = new incapsula.AiApplicationSecurityApplication("aiApplicationSecurityApplicationResource", {
applicationType: "string",
accountId: 0,
aiApplicationSecurityApplicationId: "string",
configuration: {
blockedResponseStructure: "string",
contentType: "string",
isStreaming: false,
path: "string",
promptLocation: "string",
request: {
contentPath: "string",
messagePath: "string",
rolePath: "string",
},
response: {
contentPath: "string",
endOfStreamMarker: "string",
finishReasonPath: "string",
finishReasonValue: "string",
rolePath: "string",
},
siteId: 0,
},
name: "string",
region: "string",
});
type: incapsula:AiApplicationSecurityApplication
properties:
accountId: 0
aiApplicationSecurityApplicationId: string
applicationType: string
configuration:
blockedResponseStructure: string
contentType: string
isStreaming: false
path: string
promptLocation: string
request:
contentPath: string
messagePath: string
rolePath: string
response:
contentPath: string
endOfStreamMarker: string
finishReasonPath: string
finishReasonValue: string
rolePath: string
siteId: 0
name: string
region: string
AiApplicationSecurityApplication Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The AiApplicationSecurityApplication resource accepts the following input properties:
- Application
Type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - Account
Id double - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Ai
Application stringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - Configuration
Ai
Application Security Application Configuration - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - Name string
- Name of the AI Application Security application.
- Region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- Application
Type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - Account
Id float64 - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Ai
Application stringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - Configuration
Ai
Application Security Application Configuration Args - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - Name string
- Name of the AI Application Security application.
- Region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- application_
type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - account_
id number - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai_
application_ stringsecurity_ application_ id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - configuration object
- Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name string
- Name of the AI Application Security application.
- region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- application
Type String - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - account
Id Double - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai
Application StringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - configuration
Ai
Application Security Application Configuration - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name String
- Name of the AI Application Security application.
- region String
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- application
Type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - account
Id number - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai
Application stringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - configuration
Ai
Application Security Application Configuration - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name string
- Name of the AI Application Security application.
- region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- application_
type str - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - account_
id float - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai_
application_ strsecurity_ application_ id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - configuration
Ai
Application Security Application Configuration Args - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name str
- Name of the AI Application Security application.
- region str
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- application
Type String - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - account
Id Number - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai
Application StringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - configuration Property Map
- Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name String
- Name of the AI Application Security application.
- region String
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
Outputs
All input properties are implicitly available as output properties. Additionally, the AiApplicationSecurityApplication resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing AiApplicationSecurityApplication Resource
Get an existing AiApplicationSecurityApplication resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: AiApplicationSecurityApplicationState, opts?: CustomResourceOptions): AiApplicationSecurityApplication@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
account_id: Optional[float] = None,
ai_application_security_application_id: Optional[str] = None,
application_type: Optional[str] = None,
configuration: Optional[AiApplicationSecurityApplicationConfigurationArgs] = None,
name: Optional[str] = None,
region: Optional[str] = None) -> AiApplicationSecurityApplicationfunc GetAiApplicationSecurityApplication(ctx *Context, name string, id IDInput, state *AiApplicationSecurityApplicationState, opts ...ResourceOption) (*AiApplicationSecurityApplication, error)public static AiApplicationSecurityApplication Get(string name, Input<string> id, AiApplicationSecurityApplicationState? state, CustomResourceOptions? opts = null)public static AiApplicationSecurityApplication get(String name, Output<String> id, AiApplicationSecurityApplicationState state, CustomResourceOptions options)resources: _: type: incapsula:AiApplicationSecurityApplication get: id: ${id}import {
to = incapsula_ai_application_security_application.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Account
Id double - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Ai
Application stringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - Application
Type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - Configuration
Ai
Application Security Application Configuration - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - Name string
- Name of the AI Application Security application.
- Region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- Account
Id float64 - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- Ai
Application stringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - Application
Type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - Configuration
Ai
Application Security Application Configuration Args - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - Name string
- Name of the AI Application Security application.
- Region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- account_
id number - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai_
application_ stringsecurity_ application_ id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - application_
type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - configuration object
- Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name string
- Name of the AI Application Security application.
- region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- account
Id Double - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai
Application StringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - application
Type String - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - configuration
Ai
Application Security Application Configuration - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name String
- Name of the AI Application Security application.
- region String
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- account
Id number - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai
Application stringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - application
Type string - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - configuration
Ai
Application Security Application Configuration - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name string
- Name of the AI Application Security application.
- region string
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- account_
id float - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai_
application_ strsecurity_ application_ id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - application_
type str - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - configuration
Ai
Application Security Application Configuration Args - Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name str
- Name of the AI Application Security application.
- region str
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
- account
Id Number - Numeric identifier of the account to operate on. Defaults to the account of the API credentials when omitted. Cannot be changed after the resource is created.
- ai
Application StringSecurity Application Id - UUID of the application. Used as the import key and as
application_idon the AI Application Security policy and api-key resources. - application
Type String - Deployment type of the application. One of
SDK,EDGE,API. Cannot be changed after the resource is created. - configuration Property Map
- Application configuration block. Required when
application_type = "EDGE"; not supported forSDKorAPIapplication types. Supports a single block with the following arguments: - name String
- Name of the AI Application Security application.
- region String
- Data region of the application. One of
US,EU,AU,APAC. If omitted, the application inherits the account's data region on create (the value is then stored as a computed attribute). Account-region inheritance is create-only: removing this attribute after it has been set does not revert to the account default - the last applied value is kept and the region is left unchanged. Set the attribute explicitly to move an application between regions.
Supporting Types
AiApplicationSecurityApplicationConfiguration, AiApplicationSecurityApplicationConfigurationArgs
- Blocked
Response stringStructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - Content
Type string - Content type of the inspected traffic. Default:
application/json. - Is
Streaming bool - Whether the application uses streaming responses. Default:
false. - Path string
- Request path to inspect.
- Prompt
Location string - JSONPath to the prompt within the request payload (must start with
$). - Request
Ai
Application Security Application Configuration Request - Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - Response
Ai
Application Security Application Configuration Response - Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - Site
Id double - Numeric identifier of the site the application is attached to.
- Blocked
Response stringStructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - Content
Type string - Content type of the inspected traffic. Default:
application/json. - Is
Streaming bool - Whether the application uses streaming responses. Default:
false. - Path string
- Request path to inspect.
- Prompt
Location string - JSONPath to the prompt within the request payload (must start with
$). - Request
Ai
Application Security Application Configuration Request - Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - Response
Ai
Application Security Application Configuration Response - Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - Site
Id float64 - Numeric identifier of the site the application is attached to.
- blocked_
response_ stringstructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - content_
type string - Content type of the inspected traffic. Default:
application/json. - is_
streaming bool - Whether the application uses streaming responses. Default:
false. - path string
- Request path to inspect.
- prompt_
location string - JSONPath to the prompt within the request payload (must start with
$). - request object
- Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - response object
- Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - site_
id number - Numeric identifier of the site the application is attached to.
- blocked
Response StringStructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - content
Type String - Content type of the inspected traffic. Default:
application/json. - is
Streaming Boolean - Whether the application uses streaming responses. Default:
false. - path String
- Request path to inspect.
- prompt
Location String - JSONPath to the prompt within the request payload (must start with
$). - request
Ai
Application Security Application Configuration Request - Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - response
Ai
Application Security Application Configuration Response - Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - site
Id Double - Numeric identifier of the site the application is attached to.
- blocked
Response stringStructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - content
Type string - Content type of the inspected traffic. Default:
application/json. - is
Streaming boolean - Whether the application uses streaming responses. Default:
false. - path string
- Request path to inspect.
- prompt
Location string - JSONPath to the prompt within the request payload (must start with
$). - request
Ai
Application Security Application Configuration Request - Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - response
Ai
Application Security Application Configuration Response - Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - site
Id number - Numeric identifier of the site the application is attached to.
- blocked_
response_ strstructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - content_
type str - Content type of the inspected traffic. Default:
application/json. - is_
streaming bool - Whether the application uses streaming responses. Default:
false. - path str
- Request path to inspect.
- prompt_
location str - JSONPath to the prompt within the request payload (must start with
$). - request
Ai
Application Security Application Configuration Request - Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - response
Ai
Application Security Application Configuration Response - Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - site_
id float - Numeric identifier of the site the application is attached to.
- blocked
Response StringStructure - Response body returned when a request is blocked. Must contain the
$BLOCKED_MESSAGEplaceholder, which the service substitutes with the block reason at runtime. - content
Type String - Content type of the inspected traffic. Default:
application/json. - is
Streaming Boolean - Whether the application uses streaming responses. Default:
false. - path String
- Request path to inspect.
- prompt
Location String - JSONPath to the prompt within the request payload (must start with
$). - request Property Map
- Single block describing how to extract fields from requests. All
*_pathvalues are JSONPath expressions starting with$: - response Property Map
- Single block describing how to extract fields from responses. All
*_pathvalues are JSONPath expressions starting with$: - site
Id Number - Numeric identifier of the site the application is attached to.
AiApplicationSecurityApplicationConfigurationRequest, AiApplicationSecurityApplicationConfigurationRequestArgs
- Content
Path string - JSONPath to the message content.
- Message
Path string - JSONPath to the messages array.
- Role
Path string - JSONPath to the message role.
- Content
Path string - JSONPath to the message content.
- Message
Path string - JSONPath to the messages array.
- Role
Path string - JSONPath to the message role.
- content_
path string - JSONPath to the message content.
- message_
path string - JSONPath to the messages array.
- role_
path string - JSONPath to the message role.
- content
Path String - JSONPath to the message content.
- message
Path String - JSONPath to the messages array.
- role
Path String - JSONPath to the message role.
- content
Path string - JSONPath to the message content.
- message
Path string - JSONPath to the messages array.
- role
Path string - JSONPath to the message role.
- content_
path str - JSONPath to the message content.
- message_
path str - JSONPath to the messages array.
- role_
path str - JSONPath to the message role.
- content
Path String - JSONPath to the message content.
- message
Path String - JSONPath to the messages array.
- role
Path String - JSONPath to the message role.
AiApplicationSecurityApplicationConfigurationResponse, AiApplicationSecurityApplicationConfigurationResponseArgs
- Content
Path string - JSONPath to the response content.
- End
Of stringStream Marker - Marker that signals the end of the stream.
- Finish
Reason stringPath - JSONPath to the finish-reason field.
- Finish
Reason stringValue - Value of the finish-reason field that marks completion.
- Role
Path string - JSONPath to the response role.
- Content
Path string - JSONPath to the response content.
- End
Of stringStream Marker - Marker that signals the end of the stream.
- Finish
Reason stringPath - JSONPath to the finish-reason field.
- Finish
Reason stringValue - Value of the finish-reason field that marks completion.
- Role
Path string - JSONPath to the response role.
- content_
path string - JSONPath to the response content.
- end_
of_ stringstream_ marker - Marker that signals the end of the stream.
- finish_
reason_ stringpath - JSONPath to the finish-reason field.
- finish_
reason_ stringvalue - Value of the finish-reason field that marks completion.
- role_
path string - JSONPath to the response role.
- content
Path String - JSONPath to the response content.
- end
Of StringStream Marker - Marker that signals the end of the stream.
- finish
Reason StringPath - JSONPath to the finish-reason field.
- finish
Reason StringValue - Value of the finish-reason field that marks completion.
- role
Path String - JSONPath to the response role.
- content
Path string - JSONPath to the response content.
- end
Of stringStream Marker - Marker that signals the end of the stream.
- finish
Reason stringPath - JSONPath to the finish-reason field.
- finish
Reason stringValue - Value of the finish-reason field that marks completion.
- role
Path string - JSONPath to the response role.
- content_
path str - JSONPath to the response content.
- end_
of_ strstream_ marker - Marker that signals the end of the stream.
- finish_
reason_ strpath - JSONPath to the finish-reason field.
- finish_
reason_ strvalue - Value of the finish-reason field that marks completion.
- role_
path str - JSONPath to the response role.
- content
Path String - JSONPath to the response content.
- end
Of StringStream Marker - Marker that signals the end of the stream.
- finish
Reason StringPath - JSONPath to the finish-reason field.
- finish
Reason StringValue - Value of the finish-reason field that marks completion.
- role
Path String - JSONPath to the response role.
Import
AI Application Security application can be imported using its application_id, optionally prefixed with the account_id:
$ pulumi import incapsula:index/aiApplicationSecurityApplication:AiApplicationSecurityApplication example 3f2504e0-4f89-41d3-9a0c-0305e82c3301
$ pulumi import incapsula:index/aiApplicationSecurityApplication:AiApplicationSecurityApplication example 1234567/3f2504e0-4f89-41d3-9a0c-0305e82c3301
When the account_id is omitted from the import ID it is taken from the account of the API credentials.
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- incapsula imperva/terraform-provider-incapsula
- License
- Notes
- This Pulumi package is based on the
incapsulaTerraform Provider.
published on Tuesday, Sep 15, 2026 by imperva