Skip to main content

okustera_security_group_rule (Resource)

The okustera_security_group_rule resource defines individual packet filtering rules (direction, protocol, port ranges, CIDR masks) attached to a parent security group.

Example Usage​

Allow Ingress Web Traffic (Ports 80 and 443)​

resource "okustera_security_group" "web_sg" {
name = "web-tier"
}

resource "okustera_security_group_rule" "http" {
security_group_id = okustera_security_group.web_sg.id
direction = "ingress"
protocol = "tcp"
port_range_min = 80
port_range_max = 80
remote_ip_prefix = "0.0.0.0/0"
description = "Allow public HTTP"
}

resource "okustera_security_group_rule" "https" {
security_group_id = okustera_security_group.web_sg.id
direction = "ingress"
protocol = "tcp"
port_range_min = 443
port_range_max = 443
remote_ip_prefix = "0.0.0.0/0"
description = "Allow public HTTPS"
}

Schema​

Required​

  • security_group_id (String) The ID of the parent security group. Forces replacement if changed.
  • direction (String) Traffic direction: ingress or egress.

Optional​

  • protocol (String) IP protocol: tcp, udp, icmp, or leave empty for all protocols.
  • port_range_min (Number) Starting destination port (1-65535).
  • port_range_max (Number) Ending destination port (1-65535).
  • remote_ip_prefix (String) Source or destination CIDR block. Defaults to 0.0.0.0/0.
  • description (String) Description of the rule.

Read-Only Attributes​

  • id (String) Rule UUID.

Import​

Existing rules can be imported using their UUID:

terraform import okustera_security_group_rule.http <rule_uuid>