import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../../types/input"; import * as outputs from "../../types/output"; import * as enums from "../../types/enums"; /** * Creates a new EndpointPolicy in a given project and location. */ export declare class EndpointPolicy extends pulumi.CustomResource { /** * Get an existing EndpointPolicy resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, opts?: pulumi.CustomResourceOptions): EndpointPolicy; /** * Returns true if the given object is an instance of EndpointPolicy. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is EndpointPolicy; /** * Optional. This field specifies the URL of AuthorizationPolicy resource that applies authorization policies to the inbound traffic at the matched endpoints. Refer to Authorization. If this field is not specified, authorization is disabled(no authz checks) for this endpoint. */ readonly authorizationPolicy: pulumi.Output; /** * Optional. A URL referring to a ClientTlsPolicy resource. ClientTlsPolicy can be set to specify the authentication for traffic from the proxy to the actual endpoints. More specifically, it is applied to the outgoing traffic from the proxy to the endpoint. This is typically used for sidecar model where the proxy identifies itself as endpoint to the control plane, with the connection between sidecar and endpoint requiring authentication. If this field is not set, authentication is disabled(open). Applicable only when EndpointPolicyType is SIDECAR_PROXY. */ readonly clientTlsPolicy: pulumi.Output; /** * The timestamp when the resource was created. */ readonly createTime: pulumi.Output; /** * Optional. A free-text description of the resource. Max length 1024 characters. */ readonly description: pulumi.Output; /** * A matcher that selects endpoints to which the policies should be applied. */ readonly endpointMatcher: pulumi.Output; /** * Required. Short name of the EndpointPolicy resource to be created. E.g. "CustomECS". */ readonly endpointPolicyId: pulumi.Output; /** * Optional. Set of label tags associated with the EndpointPolicy resource. */ readonly labels: pulumi.Output<{ [key: string]: string; }>; readonly location: pulumi.Output; /** * Name of the EndpointPolicy resource. It matches pattern `projects/{project}/locations/global/endpointPolicies/{endpoint_policy}`. */ readonly name: pulumi.Output; readonly project: pulumi.Output; /** * Optional. A URL referring to ServerTlsPolicy resource. ServerTlsPolicy is used to determine the authentication policy to be applied to terminate the inbound traffic at the identified backends. If this field is not set, authentication is disabled(open) for this endpoint. */ readonly serverTlsPolicy: pulumi.Output; /** * Optional. Port selector for the (matched) endpoints. If no port selector is provided, the matched config is applied to all ports. */ readonly trafficPortSelector: pulumi.Output; /** * The type of endpoint policy. This is primarily used to validate the configuration. */ readonly type: pulumi.Output; /** * The timestamp when the resource was updated. */ readonly updateTime: pulumi.Output; /** * Create a EndpointPolicy resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: EndpointPolicyArgs, opts?: pulumi.CustomResourceOptions); } /** * The set of arguments for constructing a EndpointPolicy resource. */ export interface EndpointPolicyArgs { /** * Optional. This field specifies the URL of AuthorizationPolicy resource that applies authorization policies to the inbound traffic at the matched endpoints. Refer to Authorization. If this field is not specified, authorization is disabled(no authz checks) for this endpoint. */ authorizationPolicy?: pulumi.Input; /** * Optional. A URL referring to a ClientTlsPolicy resource. ClientTlsPolicy can be set to specify the authentication for traffic from the proxy to the actual endpoints. More specifically, it is applied to the outgoing traffic from the proxy to the endpoint. This is typically used for sidecar model where the proxy identifies itself as endpoint to the control plane, with the connection between sidecar and endpoint requiring authentication. If this field is not set, authentication is disabled(open). Applicable only when EndpointPolicyType is SIDECAR_PROXY. */ clientTlsPolicy?: pulumi.Input; /** * Optional. A free-text description of the resource. Max length 1024 characters. */ description?: pulumi.Input; /** * A matcher that selects endpoints to which the policies should be applied. */ endpointMatcher: pulumi.Input; /** * Required. Short name of the EndpointPolicy resource to be created. E.g. "CustomECS". */ endpointPolicyId: pulumi.Input; /** * Optional. Set of label tags associated with the EndpointPolicy resource. */ labels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; location?: pulumi.Input; /** * Name of the EndpointPolicy resource. It matches pattern `projects/{project}/locations/global/endpointPolicies/{endpoint_policy}`. */ name?: pulumi.Input; project?: pulumi.Input; /** * Optional. A URL referring to ServerTlsPolicy resource. ServerTlsPolicy is used to determine the authentication policy to be applied to terminate the inbound traffic at the identified backends. If this field is not set, authentication is disabled(open) for this endpoint. */ serverTlsPolicy?: pulumi.Input; /** * Optional. Port selector for the (matched) endpoints. If no port selector is provided, the matched config is applied to all ports. */ trafficPortSelector?: pulumi.Input; /** * The type of endpoint policy. This is primarily used to validate the configuration. */ type: pulumi.Input; }