Class: Aws::EC2::Types::AuthorizeSecurityGroupIngressRequest

Inherits:
Struct
  • Object
show all
Defined in:
gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb

Overview

Note:

When making an API call, you may pass AuthorizeSecurityGroupIngressRequest data as a hash:

{
  cidr_ip: "String",
  from_port: 1,
  group_id: "SecurityGroupId",
  group_name: "SecurityGroupName",
  ip_permissions: [
    {
      from_port: 1,
      ip_protocol: "String",
      ip_ranges: [
        {
          cidr_ip: "String",
          description: "String",
        },
      ],
      ipv_6_ranges: [
        {
          cidr_ipv_6: "String",
          description: "String",
        },
      ],
      prefix_list_ids: [
        {
          description: "String",
          prefix_list_id: "String",
        },
      ],
      to_port: 1,
      user_id_group_pairs: [
        {
          description: "String",
          group_id: "String",
          group_name: "String",
          peering_status: "String",
          user_id: "String",
          vpc_id: "String",
          vpc_peering_connection_id: "String",
        },
      ],
    },
  ],
  ip_protocol: "String",
  source_security_group_name: "String",
  source_security_group_owner_id: "String",
  to_port: 1,
  dry_run: false,
  tag_specifications: [
    {
      resource_type: "capacity-reservation", # accepts capacity-reservation, client-vpn-endpoint, customer-gateway, carrier-gateway, dedicated-host, dhcp-options, egress-only-internet-gateway, elastic-ip, elastic-gpu, export-image-task, export-instance-task, fleet, fpga-image, host-reservation, image, import-image-task, import-snapshot-task, instance, instance-event-window, internet-gateway, ipv4pool-ec2, ipv6pool-ec2, key-pair, launch-template, local-gateway, local-gateway-route-table, local-gateway-virtual-interface, local-gateway-virtual-interface-group, local-gateway-route-table-vpc-association, local-gateway-route-table-virtual-interface-group-association, natgateway, network-acl, network-interface, network-insights-analysis, network-insights-path, placement-group, prefix-list, replace-root-volume-task, reserved-instances, route-table, security-group, security-group-rule, snapshot, spot-fleet-request, spot-instances-request, subnet, traffic-mirror-filter, traffic-mirror-session, traffic-mirror-target, transit-gateway, transit-gateway-attachment, transit-gateway-connect-peer, transit-gateway-multicast-domain, transit-gateway-route-table, volume, vpc, vpc-endpoint, vpc-endpoint-service, vpc-peering-connection, vpn-connection, vpn-gateway, vpc-flow-log
      tags: [
        {
          key: "String",
          value: "String",
        },
      ],
    },
  ],
}

Constant Summary collapse

SENSITIVE =
[]

Instance Attribute Summary collapse

Instance Attribute Details

#cidr_ipString

The IPv4 address range, in CIDR format. You can't specify this parameter when specifying a source security group. To specify an IPv6 address range, use a set of IP permissions.

Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.

Returns:

  • (String)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#dry_runBoolean

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

Returns:

  • (Boolean)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#from_portInteger

The start of port range for the TCP and UDP protocols, or an ICMP type number. For the ICMP type number, use -1 to specify all types. If you specify all ICMP types, you must specify all codes.

Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.

Returns:

  • (Integer)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#group_idString

The ID of the security group. You must specify either the security group ID or the security group name in the request. For security groups in a nondefault VPC, you must specify the security group ID.

Returns:

  • (String)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#group_nameString

[EC2-Classic, default VPC] The name of the security group. You must specify either the security group ID or the security group name in the request.

Returns:

  • (String)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#ip_permissionsArray<Types::IpPermission>

The sets of IP permissions.

Returns:



2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#ip_protocolString

The IP protocol name (tcp, udp, icmp) or number (see Protocol Numbers). To specify icmpv6, use a set of IP permissions.

[VPC only] Use -1 to specify all protocols. If you specify -1 or a protocol other than tcp, udp, or icmp, traffic on all ports is allowed, regardless of any ports you specify.

Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.

Returns:

  • (String)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#source_security_group_nameString

[EC2-Classic, default VPC] The name of the source security group. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the start of the port range, the IP protocol, and the end of the port range. Creates rules that grant full ICMP, UDP, and TCP access. To create a rule with a specific IP protocol and port range, use a set of IP permissions instead. For EC2-VPC, the source security group must be in the same VPC.

Returns:

  • (String)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#source_security_group_owner_idString

[nondefault VPC] The Amazon Web Services account ID for the source security group, if the source security group is in a different account. You can't specify this parameter in combination with the following parameters: the CIDR IP address range, the IP protocol, the start of the port range, and the end of the port range. Creates rules that grant full ICMP, UDP, and TCP access. To create a rule with a specific IP protocol and port range, use a set of IP permissions instead.

Returns:

  • (String)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#tag_specificationsArray<Types::TagSpecification>

[VPC Only] The tags applied to the security group rule.

Returns:



2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end

#to_portInteger

The end of port range for the TCP and UDP protocols, or an ICMP code number. For the ICMP code number, use -1 to specify all codes. If you specify all ICMP types, you must specify all codes.

Alternatively, use a set of IP permissions to specify multiple rules and a description for the rule.

Returns:

  • (Integer)


2888
2889
2890
2891
2892
2893
2894
2895
2896
2897
2898
2899
2900
2901
2902
# File 'gems/aws-sdk-ec2/lib/aws-sdk-ec2/types.rb', line 2888

class AuthorizeSecurityGroupIngressRequest < Struct.new(
  :cidr_ip,
  :from_port,
  :group_id,
  :group_name,
  :ip_permissions,
  :ip_protocol,
  :source_security_group_name,
  :source_security_group_owner_id,
  :to_port,
  :dry_run,
  :tag_specifications)
  SENSITIVE = []
  include Aws::Structure
end