googleComputeSslPolicy
Represents a SSL policy. SSL policies give you the ability to control the features of SSL that your SSL proxy or HTTPS load balancer negotiates.
To get more information about SslPolicy, see:
- API documentation
- How-to Guides
- Using SSL Policies
Example Usage - Ssl Policy Basic
/*Provider bindings are generated by running cdktf get.
See https://cdk.tf/provider-generation for more details.*/
import * as google from "./.gen/providers/google";
/*The following providers are missing schema information and might need manual adjustments to synthesize correctly: google.
For a more precise conversion please use the --provider flag in convert.*/
new google.computeSslPolicy.ComputeSslPolicy(this, "custom-ssl-policy", {
custom_features: [
"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384",
"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384",
],
min_tls_version: "TLS_1_2",
name: "custom-ssl-policy",
profile: "CUSTOM",
});
new google.computeSslPolicy.ComputeSslPolicy(this, "nonprod-ssl-policy", {
min_tls_version: "TLS_1_2",
name: "nonprod-ssl-policy",
profile: "MODERN",
});
new google.computeSslPolicy.ComputeSslPolicy(this, "prod-ssl-policy", {
name: "production-ssl-policy",
profile: "MODERN",
});
Argument Reference
The following arguments are supported:
name
- (Required) Name of the resource. Provided by the client when the resource is created. The name must be 1-63 characters long, and comply with RFC1035. Specifically, the name must be 1-63 characters long and match the regular expression[aZ]([AZ09]*[aZ09])?
which means the first character must be a lowercase letter, and all following characters must be a dash, lowercase letter, or digit, except the last character, which cannot be a dash.
-
description
- (Optional) An optional description of this resource. -
profile
- (Optional) Profile specifies the set of SSL features that can be used by the load balancer when negotiating SSL with clients. If usingcustom
, the set of SSL features to enable must be specified in thecustomFeatures
field. See the official documentation for information on what cipher suites each profile provides. Ifcustom
is used, thecustomFeatures
attribute must be set. Default value iscompatible
. Possible values arecompatible
,modern
,restricted
, andcustom
. -
minTlsVersion
- (Optional) The minimum version of SSL protocol that can be used by the clients to establish a connection with the load balancer. Default value istls10
. Possible values aretls10
,tls11
, andtls12
. -
customFeatures
- (Optional) Profile specifies the set of SSL features that can be used by the load balancer when negotiating SSL with clients. This can be one ofcompatible
,modern
,restricted
, orcustom
. If usingcustom
, the set of SSL features to enable must be specified in thecustomFeatures
field. See the official documentation for which ciphers are available to use. Note: this argument must be present when using thecustom
profile. This argument must not be present when using any other profile. -
project
- (Optional) The ID of the project in which the resource belongs. If it is not provided, the provider project is used.
Attributes Reference
In addition to the arguments listed above, the following computed attributes are exported:
-
id
- an identifier for the resource with formatprojects/{{project}}/global/sslPolicies/{{name}}
-
creationTimestamp
- Creation timestamp in RFC3339 text format. -
enabledFeatures
- The list of features enabled in the SSL policy. -
fingerprint
- Fingerprint of this resource. A hash of the contents stored in this object. This field is used in optimistic locking. -
selfLink
- The URI of the created resource.
Timeouts
This resource provides the following Timeouts configuration options:
create
- Default is 20 minutes.update
- Default is 20 minutes.delete
- Default is 20 minutes.
Import
SslPolicy can be imported using any of these accepted formats:
$ terraform import google_compute_ssl_policy.default projects/{{project}}/global/sslPolicies/{{name}}
$ terraform import google_compute_ssl_policy.default {{project}}/{{name}}
$ terraform import google_compute_ssl_policy.default {{name}}
User Project Overrides
This resource supports User Project Overrides.