Skip to content

xcsh_aws_vpc_site (Data Source)

Retrieves information about a AWS VPC Site resource in F5 Distributed Cloud for deploying F5 sites within AWS VPC environments. This is a read-only data source.

~> Note: For more information, see the AWS VPC Site API documentation.

# AWSVPCSite Data Source Example
terraform {
required_version = ">= 1.0"
required_providers {
xcsh = {
source = "f5-sales-demo/xcsh"
version = ">= 0.1.0"
}
}
}
# Look up an existing AWSVPCSite by name
data "xcsh_aws_vpc_site" "example" {
name = "example-aws-vpc-site"
namespace = "staging"
}
output "aws_vpc_site_id" {
value = data.xcsh_aws_vpc_site.example.id
}

-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.

🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.

~> Dependencies — This resource requires: cloud_credentials.

• name - Required String
Name of the AWSVPCSite

• namespace - Required String
Namespace where the AWSVPCSite exists

In addition to all arguments above, the following attributes are exported:

• address - Optional String
Site’s geographical address that can be used to determine its latitude and longitude

• admin_password - Optional String
SecretType is used in an object to indicate a sensitive/confidential field

• annotations - Optional Map
Annotations applied to this resource

• aws_cred - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• aws_region - Optional String
AWS Region. Name for AWS Region

• block_all_services - Optional Object
Enable this option

• blocked_services - Optional String
Disable node local services on this site

• coordinates - Optional String
Coordinates of the site which provides the site physical location

• custom_dns - Optional String
Custom DNS is the configured for specify CE site

• custom_security_group - Optional String
Enter pre created security groups for slo(Site Local Outside) and SLI(Site Local Inside) interface. Supported only for sites deployed on existing VPC

• default_blocked_services - Optional Object
Enable this option

• description - Optional String
Description of the AWSVPCSite

• direct_connect_disabled - Optional Object
Enable this option

• direct_connect_enabled - Optional String
Direct Connect Configuration. Direct Connect Configuration

• disable_encryption - Optional Object
Configuration parameter for disable encryption

• disable_internet_vip - Optional Object
Enable this option

• disk_size - Optional Number
Disk size to be used for this instance in GiB. 80 is 80 GiB

• egress_gateway_default - Optional Object
Configuration parameter for egress gateway default

• egress_nat_gw - Optional String
With this option, egress site traffic will be routed through an Network Address Translation(NAT) Gateway

• egress_virtual_private_gateway - Optional String
With this option, egress site traffic will be routed through an Virtual Private Gateway

• enable_encryption - Optional String
Configuration parameter for enable encryption

• enable_internet_vip - Optional Object
Enable this option

• f5_orchestrated_routing - Optional Object
Enable this option

• f5xc_security_group - Optional Object
Enable this option

• id - Optional String
Unique identifier for the resource

• ingress_egress_gw - Optional String
Configuration parameter for ingress egress gw

• ingress_gw - Optional String
AWS Ingress Gateway. Single interface AWS ingress site

• instance_type - Optional String
Select Instance size based on performance needed

• kubernetes_upgrade_drain - Optional String
Specify how worker nodes within a site will be upgraded

• labels - Optional Map
Labels applied to this resource

• log_receiver - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• logs_streaming_disabled - Optional Object
Enable this option

• manual_routing - Optional Object
Enable this option

• no_worker_nodes - Optional Object
Configuration parameter for no worker nodes

• nodes_per_az - Optional Number
Desired Worker Nodes Per AZ. Max limit is up to 21

• offline_survivability_mode - Optional String
Offline Survivability allows the Site to continue functioning normally without traffic loss during periods of connectivity loss to the Regional Edge (RE) or the Global Controller (GC). When this feature is enabled, a site can continue to function as is with existing configuration for upto 7

• os - Optional String
Select the F5XC Operating System Version for the site. By default, latest available OS Version will be used. Refer to release notes to find required released OS versions

• private_connectivity - Optional String
Configuration parameter for private connectivity

• ssh_key - Optional String
Public SSH key. Public SSH key for accessing the site

• sw - Optional String
Select the F5XC Software Version for the site. By default, latest available F5XC Software Version will be used. Refer to release notes to find required released SW versions

• tags - Optional Map
AWS Tags is a label consisting of a user-defined key and value. It helps to manage, identify, organize, search for, and filter resources in AWS console

• total_nodes - Optional Number
Total number of worker nodes to be deployed across all AZ’s used in the Site

• voltstack_cluster - Optional String
App Stack cluster of single interface AWS nodes

• vpc - Optional String
Defines choice about AWS VPC for a view

• blindfold_secret_info - Optional String
BlindfoldSecretInfoType specifies information about the Secret managed by F5XC Secret Management

• clear_secret_info - Optional String
ClearSecretInfoType specifies information about the Secret that is not encrypted

• decryption_provider - Optional String
Name of the Secret Management Access object that contains information about the backend Secret Management service

• location - Optional String
Location is the uri_ref. It could be in URL format for string:/// Or it could be a path if the store provider is an HTTP/HTTPS location

• store_provider - Optional String
Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///

• provider_ref - Optional String
Name of the Secret Management Access object that contains information about the store to GET encrypted bytes This field needs to be provided only if the URL scheme is not string:///

• url - Optional String
URL of the secret. Currently supported URL schemes is string:///. For string:/// scheme, Secret needs to be encoded Base64 format. When asked for this secret, caller will GET Secret bytes after Base64 decoding

• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

• blocked_service - Optional List
Disable Node Local Services. Blocking or denial configuration

• dns - Optional Object
Enable this option

• network_type - Optional String Defaults to VIRTUAL_NETWORK_SITE_LOCAL
Possible values are VIRTUAL_NETWORK_SITE_LOCAL, VIRTUAL_NETWORK_SITE_LOCAL_INSIDE, VIRTUAL_NETWORK_PER_SITE, VIRTUAL_NETWORK_PUBLIC, VIRTUAL_NETWORK_GLOBAL, VIRTUAL_NETWORK_SITE_SERVICE, VIRTUAL_NETWORK_VER_INTERNAL, VIRTUAL_NETWORK_SITE_LOCAL_INSIDE_OUTSIDE, VIRTUAL_NETWORK_IP_AUTO, VIRTUAL_NETWORK_VOLTADN_PRIVATE_NETWORK, VIRTUAL_NETWORK_SRV6_NETWORK, VIRTUAL_NETWORK_IP_FABRIC, VIRTUAL_NETWORK_SEGMENT, VIRTUAL_NETWORK_MANAGEMENT
[Enum: VIRTUAL_NETWORK_SITE_LOCAL|VIRTUAL_NETWORK_SITE_LOCAL_INSIDE|VIRTUAL_NETWORK_PER_SITE|VIRTUAL_NETWORK_PUBLIC|VIRTUAL_NETWORK_GLOBAL|VIRTUAL_NETWORK_SITE_SERVICE|VIRTUAL_NETWORK_VER_INTERNAL|VIRTUAL_NETWORK_SITE_LOCAL_INSIDE_OUTSIDE|VIRTUAL_NETWORK_IP_AUTO|VIRTUAL_NETWORK_VOLTADN_PRIVATE_NETWORK|VIRTUAL_NETWORK_SRV6_NETWORK|VIRTUAL_NETWORK_IP_FABRIC|VIRTUAL_NETWORK_SEGMENT|VIRTUAL_NETWORK_MANAGEMENT] Different types of virtual networks understood by the system Virtual-network of type VIRTUAL_NETWORK_SITE_LOCAL provides connectivity to public (outside) network. This is an insecure network and is connected to public internet via NAT Gateways/firwalls Virtual-network of this type is local to

• ssh - Optional Object
Enable this option

• web_user_interface - Optional Object
Enable this option


A coordinates block supports the following:

• latitude - Optional Number
Latitude. Latitude of the site location

• longitude - Optional Number
Longitude. Longitude of site location

A custom_dns block supports the following:

• inside_nameserver - Optional String
Optional DNS server IP to be used for name resolution in inside network

• outside_nameserver - Optional String
Optional DNS server IP to be used for name resolution in outside network

A custom_security_group block supports the following:

• inside_security_group_id - Optional String
Security Group ID to be attached to SLI(Site Local Inside) Interface

• outside_security_group_id - Optional String
Security Group ID to be attached to SLO(Site Local Outside) Interface

A default_blocked_services block supports the following:

A direct_connect_disabled block supports the following:

A direct_connect_enabled block supports the following:

• auto_asn - Optional Object
Enable this option

• custom_asn - Optional Number
Custom Autonomous System Number

• hosted_vifs - Optional String
AWS Direct Connect Hosted VIF Configuration

• standard_vifs - Optional Object
Configuration parameter for standard vifs

An auto_asn block (within direct_connect_enabled) supports the following:

A hosted_vifs block (within direct_connect_enabled) supports the following:

• site_registration_over_direct_connect - Optional String
CloudLink ADN Network Config

• site_registration_over_internet - Optional Object
Enable this option

• vif_list - Optional List
List of Hosted VIF Config. List of Hosted VIF Config

Direct Connect Enabled Hosted Vifs Site Registration Over Direct Connect

Section titled “Direct Connect Enabled Hosted Vifs Site Registration Over Direct Connect”

Deeply nested Connect block collapsed for readability.

Direct Connect Enabled Hosted Vifs Site Registration Over internet

Section titled “Direct Connect Enabled Hosted Vifs Site Registration Over internet”

Deeply nested internet block collapsed for readability.

Direct Connect Enabled Hosted Vifs Vif List

Section titled “Direct Connect Enabled Hosted Vifs Vif List”

A vif_list block (within direct_connect_enabled.hosted_vifs) supports the following:

• other_region - Optional String
Possible values are af-south-1, ap-east-1, ap-northeast-1, ap-northeast-2, ap-south-1, ap-southeast-1, ap-southeast-2, ap-southeast-3, CA-central-1, eu-central-1, eu-north-1, eu-south-1, eu-west-1, eu-west-2, eu-west-3, me-south-1, sa-east-1, us-east-1, us-east-2, us-west-1, us-west-2
[Enum: af-south-1|ap-east-1|ap-northeast-1|ap-northeast-2|ap-south-1|ap-southeast-1|ap-southeast-2|ap-southeast-3|CA-central-1|eu-central-1|eu-north-1|eu-south-1|eu-west-1|eu-west-2|eu-west-3|me-south-1|sa-east-1|us-east-1|us-east-2|us-west-1|us-west-2] Other Region

• same_as_site_region - Optional Object
Enable this option

• vif_id - Optional String
AWS Direct Connect VIF ID that needs to be connected to the site

Direct Connect Enabled Hosted Vifs Vif List Same As Site Region

Section titled “Direct Connect Enabled Hosted Vifs Vif List Same As Site Region”

Deeply nested Region block collapsed for readability.

A standard_vifs block (within direct_connect_enabled) supports the following:

A disable_encryption block supports the following:

A disable_internet_vip block supports the following:

An egress_gateway_default block supports the following:

An egress_nat_gw block supports the following:

• nat_gw_id - Optional String
Existing NAT Gateway ID

An egress_virtual_private_gateway block supports the following:

• vgw_id - Optional String
Existing Virtual Private Gateway ID

An enable_encryption block supports the following:

• kms_key_id - Optional String
AWS KMS Key to be used to encrypt the disk attached to the VM

An enable_internet_vip block supports the following:

A f5_orchestrated_routing block supports the following:

A f5xc_security_group block supports the following:

An ingress_egress_gw block supports the following:

• active_enhanced_firewall_policies - Optional String
List of Enhanced Firewall Policies These policies use session-based rules and provide all OPTIONS available under firewall policies with an additional option for service insertion

• active_forward_proxy_policies - Optional String
Ordered List of Forward Proxy Policies active

• active_network_policies - Optional String
Configuration parameter for active network policies

• allowed_vip_port - Optional String
Defines the TCP port(s) which will be opened on the cloud loadbalancer. Such that the client can use the cloud VIP IP and port combination to reach TCP/HTTP LB configured on the F5XC Site

• allowed_vip_port_sli - Optional String
Defines the TCP port(s) which will be opened on the cloud loadbalancer. Such that the client can use the cloud VIP IP and port combination to reach TCP/HTTP LB configured on the F5XC Site

• aws_certified_hw - Optional String
[Enum: AWS-byol-multi-nic-voltmesh] AWS Certified Hardware. Name for AWS certified hardware. The only possible value is AWS-byol-multi-nic-voltmesh

• az_nodes - Optional List
Only Single AZ or Three AZ(s) nodes are supported currently

• dc_cluster_group_inside_vn - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• dc_cluster_group_outside_vn - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• forward_proxy_allow_all - Optional Object
Configuration parameter for forward proxy allow all

• global_network_list - Optional String
Global Network Connection List. List of global network connections

• inside_static_routes - Optional String
Configuration parameter for inside static routes

• no_dc_cluster_group - Optional Object
Enable this option

• no_forward_proxy - Optional Object
Configuration parameter for no forward proxy

• no_global_network - Optional Object
Configuration parameter for no global network

• no_inside_static_routes - Optional Object
Configuration parameter for no inside static routes

• no_network_policy - Optional Object
Policy configuration for this feature

• no_outside_static_routes - Optional Object
Configuration parameter for no outside static routes

• outside_static_routes - Optional String
Configuration parameter for outside static routes

• performance_enhancement_mode - Optional String
Optimize the site for L3 or L7 traffic processing. L7 optimized is the default

• sm_connection_public_ip - Optional Object
Enable this option

• sm_connection_pvt_ip - Optional Object
Enable this option

Ingress Egress Gw Active Enhanced Firewall Policies

Section titled “Ingress Egress Gw Active Enhanced Firewall Policies”

An active_enhanced_firewall_policies block (within ingress_egress_gw) supports the following:

• enhanced_firewall_policies - Optional List
Ordered List of Enhanced Firewall Policies active

Ingress Egress Gw Active Enhanced Firewall Policies Enhanced Firewall Policies

Section titled “Ingress Egress Gw Active Enhanced Firewall Policies Enhanced Firewall Policies”

Deeply nested Policies block collapsed for readability.

Ingress Egress Gw Active Forward Proxy Policies

Section titled “Ingress Egress Gw Active Forward Proxy Policies”

An active_forward_proxy_policies block (within ingress_egress_gw) supports the following:

• forward_proxy_policies - Optional List
Ordered List of Forward Proxy Policies active

Ingress Egress Gw Active Forward Proxy Policies Forward Proxy Policies

Section titled “Ingress Egress Gw Active Forward Proxy Policies Forward Proxy Policies”

Deeply nested Policies block collapsed for readability.

An active_network_policies block (within ingress_egress_gw) supports the following:

• network_policies - Optional List
Ordered List of Firewall Policies active for this network firewall

Ingress Egress Gw Active Network Policies Network Policies

Section titled “Ingress Egress Gw Active Network Policies Network Policies”

Deeply nested Policies block collapsed for readability.

An allowed_vip_port block (within ingress_egress_gw) supports the following:

• custom_ports - Optional String
Custom Ports. List of Custom port

• disable_allowed_vip_port - Optional Object
Enable this option

• use_http_https_port - Optional Object
Enable this option

• use_http_port - Optional Object
Enable this option

• use_https_port - Optional Object
Enable this option

Ingress Egress Gw Allowed VIP Port Custom Ports

Section titled “Ingress Egress Gw Allowed VIP Port Custom Ports”

Deeply nested Ports block collapsed for readability.

Ingress Egress Gw Allowed VIP Port Disable Allowed VIP Port

Section titled “Ingress Egress Gw Allowed VIP Port Disable Allowed VIP Port”

Deeply nested Port block collapsed for readability.

Ingress Egress Gw Allowed VIP Port Use HTTP HTTPS Port

Section titled “Ingress Egress Gw Allowed VIP Port Use HTTP HTTPS Port”

Deeply nested Port block collapsed for readability.

Ingress Egress Gw Allowed VIP Port Use HTTP Port

Section titled “Ingress Egress Gw Allowed VIP Port Use HTTP Port”

Deeply nested Port block collapsed for readability.

Ingress Egress Gw Allowed VIP Port Use HTTPS Port

Section titled “Ingress Egress Gw Allowed VIP Port Use HTTPS Port”

Deeply nested Port block collapsed for readability.

An allowed_vip_port_sli block (within ingress_egress_gw) supports the following:

• custom_ports - Optional String
Custom Ports. List of Custom port

• disable_allowed_vip_port - Optional Object
Enable this option

• use_http_https_port - Optional Object
Enable this option

• use_http_port - Optional Object
Enable this option

• use_https_port - Optional Object
Enable this option

Ingress Egress Gw Allowed VIP Port SLI Custom Ports

Section titled “Ingress Egress Gw Allowed VIP Port SLI Custom Ports”

Deeply nested Ports block collapsed for readability.

Ingress Egress Gw Allowed VIP Port SLI Disable Allowed VIP Port

Section titled “Ingress Egress Gw Allowed VIP Port SLI Disable Allowed VIP Port”

Deeply nested Port block collapsed for readability.

Ingress Egress Gw Allowed VIP Port SLI Use HTTP HTTPS Port

Section titled “Ingress Egress Gw Allowed VIP Port SLI Use HTTP HTTPS Port”

Deeply nested Port block collapsed for readability.

Ingress Egress Gw Allowed VIP Port SLI Use HTTP Port

Section titled “Ingress Egress Gw Allowed VIP Port SLI Use HTTP Port”

Deeply nested Port block collapsed for readability.

Ingress Egress Gw Allowed VIP Port SLI Use HTTPS Port

Section titled “Ingress Egress Gw Allowed VIP Port SLI Use HTTPS Port”

Deeply nested Port block collapsed for readability.

An az_nodes block (within ingress_egress_gw) supports the following:

• aws_az_name - Optional String
AWS availability zone, must be consistent with the selected AWS region

• inside_subnet - Optional String
Configuration parameter for inside subnet

• outside_subnet - Optional String
Configuration parameter for outside subnet

• reserved_inside_subnet - Optional Object
Configuration parameter for reserved inside subnet

• workload_subnet - Optional String
Configuration parameter for workload subnet

An inside_subnet block (within ingress_egress_gw.az_nodes) supports the following:

• existing_subnet_id - Optional String
Information about existing subnet ID

• subnet_param - Optional String
Parameters for creating a new cloud subnet

Ingress Egress Gw Az Nodes Inside Subnet Subnet Param

Section titled “Ingress Egress Gw Az Nodes Inside Subnet Subnet Param”

Deeply nested Param block collapsed for readability.

An outside_subnet block (within ingress_egress_gw.az_nodes) supports the following:

• existing_subnet_id - Optional String
Information about existing subnet ID

• subnet_param - Optional String
Parameters for creating a new cloud subnet

Ingress Egress Gw Az Nodes Outside Subnet Subnet Param

Section titled “Ingress Egress Gw Az Nodes Outside Subnet Subnet Param”

Deeply nested Param block collapsed for readability.

Ingress Egress Gw Az Nodes Reserved Inside Subnet

Section titled “Ingress Egress Gw Az Nodes Reserved Inside Subnet”

Deeply nested Subnet block collapsed for readability.

Ingress Egress Gw Az Nodes Workload Subnet

Section titled “Ingress Egress Gw Az Nodes Workload Subnet”

A workload_subnet block (within ingress_egress_gw.az_nodes) supports the following:

• existing_subnet_id - Optional String
Information about existing subnet ID

• subnet_param - Optional String
Parameters for creating a new cloud subnet

Ingress Egress Gw Az Nodes Workload Subnet Subnet Param

Section titled “Ingress Egress Gw Az Nodes Workload Subnet Subnet Param”

Deeply nested Param block collapsed for readability.

Ingress Egress Gw Dc Cluster Group Inside Vn

Section titled “Ingress Egress Gw Dc Cluster Group Inside Vn”

Deeply nested Vn block collapsed for readability.

Ingress Egress Gw Dc Cluster Group Outside Vn

Section titled “Ingress Egress Gw Dc Cluster Group Outside Vn”

Deeply nested Vn block collapsed for readability.

A forward_proxy_allow_all block (within ingress_egress_gw) supports the following:

A global_network_list block (within ingress_egress_gw) supports the following:

• global_network_connections - Optional List
Global Network Connections. Global network connections

Ingress Egress Gw Global Network List Global Network Connections

Section titled “Ingress Egress Gw Global Network List Global Network Connections”

Deeply nested Connections block collapsed for readability.

Ingress Egress Gw Global Network List Global Network Connections SLI To Global DR

Section titled “Ingress Egress Gw Global Network List Global Network Connections SLI To Global DR”

Deeply nested DR block collapsed for readability.

Ingress Egress Gw Global Network List Global Network Connections SLI To Global DR Global Vn

Section titled “Ingress Egress Gw Global Network List Global Network Connections SLI To Global DR Global Vn”

Deeply nested Vn block collapsed for readability.

Ingress Egress Gw Global Network List Global Network Connections Slo To Global DR

Section titled “Ingress Egress Gw Global Network List Global Network Connections Slo To Global DR”

Deeply nested DR block collapsed for readability.

Ingress Egress Gw Global Network List Global Network Connections Slo To Global DR Global Vn

Section titled “Ingress Egress Gw Global Network List Global Network Connections Slo To Global DR Global Vn”

Deeply nested Vn block collapsed for readability.

An inside_static_routes block (within ingress_egress_gw) supports the following:

• static_route_list - Optional List
List of Static Routes. List of Static routes

Ingress Egress Gw Inside Static Routes Static Route List

Section titled “Ingress Egress Gw Inside Static Routes Static Route List”

Deeply nested List block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route”

Deeply nested Route block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Labels

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Labels”

Deeply nested Labels block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop”

Deeply nested Nexthop block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Interface

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Interface”

Deeply nested Interface block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address”

Deeply nested Address block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv4

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv4”

Deeply nested IPv4 block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv6

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv6”

Deeply nested IPv6 block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Subnets

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Subnets”

Deeply nested Subnets block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Subnets IPv4

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Subnets IPv4”

Deeply nested IPv4 block collapsed for readability.

Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Subnets IPv6

Section titled “Ingress Egress Gw Inside Static Routes Static Route List Custom Static Route Subnets IPv6”

Deeply nested IPv6 block collapsed for readability.

A no_dc_cluster_group block (within ingress_egress_gw) supports the following:

A no_forward_proxy block (within ingress_egress_gw) supports the following:

A no_global_network block (within ingress_egress_gw) supports the following:

A no_inside_static_routes block (within ingress_egress_gw) supports the following:

A no_network_policy block (within ingress_egress_gw) supports the following:

Ingress Egress Gw No Outside Static Routes

Section titled “Ingress Egress Gw No Outside Static Routes”

A no_outside_static_routes block (within ingress_egress_gw) supports the following:

An outside_static_routes block (within ingress_egress_gw) supports the following:

• static_route_list - Optional List
List of Static Routes. List of Static routes

Ingress Egress Gw Outside Static Routes Static Route List

Section titled “Ingress Egress Gw Outside Static Routes Static Route List”

Deeply nested List block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route”

Deeply nested Route block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Labels

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Labels”

Deeply nested Labels block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop”

Deeply nested Nexthop block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Interface

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Interface”

Deeply nested Interface block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address”

Deeply nested Address block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv4

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv4”

Deeply nested IPv4 block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv6

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv6”

Deeply nested IPv6 block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Subnets

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Subnets”

Deeply nested Subnets block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Subnets IPv4

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Subnets IPv4”

Deeply nested IPv4 block collapsed for readability.

Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Subnets IPv6

Section titled “Ingress Egress Gw Outside Static Routes Static Route List Custom Static Route Subnets IPv6”

Deeply nested IPv6 block collapsed for readability.

Ingress Egress Gw Performance Enhancement Mode

Section titled “Ingress Egress Gw Performance Enhancement Mode”

A performance_enhancement_mode block (within ingress_egress_gw) supports the following:

• perf_mode_l3_enhanced - Optional String
Configuration parameter for perf mode l3 enhanced

• perf_mode_l7_enhanced - Optional String
Configuration parameter for perf mode l7 enhanced

Ingress Egress Gw Performance Enhancement Mode Perf Mode L3 Enhanced

Section titled “Ingress Egress Gw Performance Enhancement Mode Perf Mode L3 Enhanced”

Deeply nested Enhanced block collapsed for readability.

Ingress Egress Gw Performance Enhancement Mode Perf Mode L3 Enhanced Jumbo

Section titled “Ingress Egress Gw Performance Enhancement Mode Perf Mode L3 Enhanced Jumbo”

Deeply nested Jumbo block collapsed for readability.

Ingress Egress Gw Performance Enhancement Mode Perf Mode L3 Enhanced No Jumbo

Section titled “Ingress Egress Gw Performance Enhancement Mode Perf Mode L3 Enhanced No Jumbo”

Deeply nested Jumbo block collapsed for readability.

Ingress Egress Gw Performance Enhancement Mode Perf Mode L7 Enhanced

Section titled “Ingress Egress Gw Performance Enhancement Mode Perf Mode L7 Enhanced”

Deeply nested Enhanced block collapsed for readability.

Ingress Egress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Disabled

Section titled “Ingress Egress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Disabled”

Deeply nested Disabled block collapsed for readability.

Ingress Egress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Enabled

Section titled “Ingress Egress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Enabled”

Deeply nested Enabled block collapsed for readability.

A sm_connection_public_ip block (within ingress_egress_gw) supports the following:

A sm_connection_pvt_ip block (within ingress_egress_gw) supports the following:

An ingress_gw block supports the following:

• allowed_vip_port - Optional String
Defines the TCP port(s) which will be opened on the cloud loadbalancer. Such that the client can use the cloud VIP IP and port combination to reach TCP/HTTP LB configured on the F5XC Site

• aws_certified_hw - Optional String
[Enum: AWS-byol-voltmesh] AWS Certified Hardware. Name for AWS certified hardware. The only possible value is AWS-byol-voltmesh

• az_nodes - Optional List
Only Single AZ or Three AZ(s) nodes are supported currently

• performance_enhancement_mode - Optional String
Optimize the site for L3 or L7 traffic processing. L7 optimized is the default

An allowed_vip_port block (within ingress_gw) supports the following:

• custom_ports - Optional String
Custom Ports. List of Custom port

• disable_allowed_vip_port - Optional Object
Enable this option

• use_http_https_port - Optional Object
Enable this option

• use_http_port - Optional Object
Enable this option

• use_https_port - Optional Object
Enable this option

A custom_ports block (within ingress_gw.allowed_vip_port) supports the following:

• port_ranges - Optional String
Port Ranges. Port Ranges

Ingress Gw Allowed VIP Port Disable Allowed VIP Port

Section titled “Ingress Gw Allowed VIP Port Disable Allowed VIP Port”

Deeply nested Port block collapsed for readability.

Ingress Gw Allowed VIP Port Use HTTP HTTPS Port

Section titled “Ingress Gw Allowed VIP Port Use HTTP HTTPS Port”

Deeply nested Port block collapsed for readability.

Deeply nested Port block collapsed for readability.

Ingress Gw Allowed VIP Port Use HTTPS Port

Section titled “Ingress Gw Allowed VIP Port Use HTTPS Port”

Deeply nested Port block collapsed for readability.

An az_nodes block (within ingress_gw) supports the following:

• aws_az_name - Optional String
AWS availability zone, must be consistent with the selected AWS region

• local_subnet - Optional String
Configuration parameter for local subnet

A local_subnet block (within ingress_gw.az_nodes) supports the following:

• existing_subnet_id - Optional String
Information about existing subnet ID

• subnet_param - Optional String
Parameters for creating a new cloud subnet

Ingress Gw Az Nodes Local Subnet Subnet Param

Section titled “Ingress Gw Az Nodes Local Subnet Subnet Param”

Deeply nested Param block collapsed for readability.

A performance_enhancement_mode block (within ingress_gw) supports the following:

• perf_mode_l3_enhanced - Optional String
Configuration parameter for perf mode l3 enhanced

• perf_mode_l7_enhanced - Optional String
Configuration parameter for perf mode l7 enhanced

Ingress Gw Performance Enhancement Mode Perf Mode L3 Enhanced

Section titled “Ingress Gw Performance Enhancement Mode Perf Mode L3 Enhanced”

Deeply nested Enhanced block collapsed for readability.

Ingress Gw Performance Enhancement Mode Perf Mode L3 Enhanced Jumbo

Section titled “Ingress Gw Performance Enhancement Mode Perf Mode L3 Enhanced Jumbo”

Deeply nested Jumbo block collapsed for readability.

Ingress Gw Performance Enhancement Mode Perf Mode L3 Enhanced No Jumbo

Section titled “Ingress Gw Performance Enhancement Mode Perf Mode L3 Enhanced No Jumbo”

Deeply nested Jumbo block collapsed for readability.

Ingress Gw Performance Enhancement Mode Perf Mode L7 Enhanced

Section titled “Ingress Gw Performance Enhancement Mode Perf Mode L7 Enhanced”

Deeply nested Enhanced block collapsed for readability.

Ingress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Disabled

Section titled “Ingress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Disabled”

Deeply nested Disabled block collapsed for readability.

Ingress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Enabled

Section titled “Ingress Gw Performance Enhancement Mode Perf Mode L7 Enhanced Jumbo Enabled”

Deeply nested Enabled block collapsed for readability.

A kubernetes_upgrade_drain block supports the following:

• disable_upgrade_drain - Optional Object
Configuration parameter for disable upgrade drain

• enable_upgrade_drain - Optional String
Specify batch upgrade settings for worker nodes within a site

Kubernetes Upgrade Drain Disable Upgrade Drain

Section titled “Kubernetes Upgrade Drain Disable Upgrade Drain”

A disable_upgrade_drain block (within kubernetes_upgrade_drain) supports the following:

Kubernetes Upgrade Drain Enable Upgrade Drain

Section titled “Kubernetes Upgrade Drain Enable Upgrade Drain”

An enable_upgrade_drain block (within kubernetes_upgrade_drain) supports the following:

• disable_vega_upgrade_mode - Optional Object
Configuration parameter for disable vega upgrade mode

• drain_max_unavailable_node_count - Optional Number
Node Batch Size Count

• drain_max_unavailable_node_percentage - Optional Number
Maximum percentage of nodes unavailable during upgrade draining

• drain_node_timeout - Optional Number
Seconds to wait before initiating upgrade on the next set of nodes. Setting it to 0 will wait indefinitely for all services on nodes to be upgraded gracefully before proceeding to the next set of nodes. (Warning: It may block upgrade if services on a node cannot be gracefully upgraded. It is

• enable_vega_upgrade_mode - Optional Object
Configuration parameter for enable vega upgrade mode

Kubernetes Upgrade Drain Enable Upgrade Drain Disable Vega Upgrade Mode

Section titled “Kubernetes Upgrade Drain Enable Upgrade Drain Disable Vega Upgrade Mode”

Deeply nested Mode block collapsed for readability.

Kubernetes Upgrade Drain Enable Upgrade Drain Enable Vega Upgrade Mode

Section titled “Kubernetes Upgrade Drain Enable Upgrade Drain Enable Vega Upgrade Mode”

Deeply nested Mode block collapsed for readability.

A log_receiver block supports the following:

• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

A logs_streaming_disabled block supports the following:

A manual_routing block supports the following:

A no_worker_nodes block supports the following:

An offline_survivability_mode block supports the following:

• enable_offline_survivability_mode - Optional Object
Configuration parameter for enable offline survivability mode

• no_offline_survivability_mode - Optional Object
Configuration parameter for no offline survivability mode

Offline Survivability Mode Enable Offline Survivability Mode

Section titled “Offline Survivability Mode Enable Offline Survivability Mode”

An enable_offline_survivability_mode block (within offline_survivability_mode) supports the following:

Offline Survivability Mode No Offline Survivability Mode

Section titled “Offline Survivability Mode No Offline Survivability Mode”

A no_offline_survivability_mode block (within offline_survivability_mode) supports the following:

An os block supports the following:

• default_os_version - Optional Object
Enable this option

• operating_system_version - Optional String
Specify a OS version to be used e.g. 9.2024.6

A default_os_version block (within os) supports the following:

A private_connectivity block supports the following:

• cloud_link - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• inside - Optional Object
Enable this option

• outside - Optional Object
Enable this option

A cloud_link block (within private_connectivity) supports the following:

• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

An inside block (within private_connectivity) supports the following:

An outside block (within private_connectivity) supports the following:

A sw block supports the following:

• default_sw_version - Optional Object
Enable this option

• volterra_software_version - Optional String
Specify a F5XC Software Version to be used e.g. Crt-20210329-1002

A default_sw_version block (within sw) supports the following:

A voltstack_cluster block supports the following:

• active_enhanced_firewall_policies - Optional String
List of Enhanced Firewall Policies These policies use session-based rules and provide all OPTIONS available under firewall policies with an additional option for service insertion

• active_forward_proxy_policies - Optional String
Ordered List of Forward Proxy Policies active

• active_network_policies - Optional String
Configuration parameter for active network policies

• allowed_vip_port - Optional String
Defines the TCP port(s) which will be opened on the cloud loadbalancer. Such that the client can use the cloud VIP IP and port combination to reach TCP/HTTP LB configured on the F5XC Site

• aws_certified_hw - Optional String
[Enum: AWS-byol-voltstack-combo] AWS Certified Hardware. Name for AWS certified hardware. The only possible value is AWS-byol-voltstack-combo

• az_nodes - Optional List
Only Single AZ or Three AZ(s) nodes are supported currently

• dc_cluster_group - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• default_storage - Optional Object
Configuration parameter for default storage

• forward_proxy_allow_all - Optional Object
Configuration parameter for forward proxy allow all

• global_network_list - Optional String
Global Network Connection List. List of global network connections

• k8s_cluster - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name

• no_dc_cluster_group - Optional Object
Enable this option

• no_forward_proxy - Optional Object
Configuration parameter for no forward proxy

• no_global_network - Optional Object
Configuration parameter for no global network

• no_k8s_cluster - Optional Object
Enable this option

• no_network_policy - Optional Object
Policy configuration for this feature

• no_outside_static_routes - Optional Object
Configuration parameter for no outside static routes

• outside_static_routes - Optional String
Configuration parameter for outside static routes

• sm_connection_public_ip - Optional Object
Enable this option

• sm_connection_pvt_ip - Optional Object
Enable this option

• storage_class_list - Optional String
Add additional custom storage classes in Kubernetes for this site

Voltstack Cluster Active Enhanced Firewall Policies

Section titled “Voltstack Cluster Active Enhanced Firewall Policies”

An active_enhanced_firewall_policies block (within voltstack_cluster) supports the following:

• enhanced_firewall_policies - Optional List
Ordered List of Enhanced Firewall Policies active

Voltstack Cluster Active Enhanced Firewall Policies Enhanced Firewall Policies

Section titled “Voltstack Cluster Active Enhanced Firewall Policies Enhanced Firewall Policies”

Deeply nested Policies block collapsed for readability.

Voltstack Cluster Active Forward Proxy Policies

Section titled “Voltstack Cluster Active Forward Proxy Policies”

An active_forward_proxy_policies block (within voltstack_cluster) supports the following:

• forward_proxy_policies - Optional List
Ordered List of Forward Proxy Policies active

Voltstack Cluster Active Forward Proxy Policies Forward Proxy Policies

Section titled “Voltstack Cluster Active Forward Proxy Policies Forward Proxy Policies”

Deeply nested Policies block collapsed for readability.

An active_network_policies block (within voltstack_cluster) supports the following:

• network_policies - Optional List
Ordered List of Firewall Policies active for this network firewall

Voltstack Cluster Active Network Policies Network Policies

Section titled “Voltstack Cluster Active Network Policies Network Policies”

A network_policies block (within voltstack_cluster.active_network_policies) supports the following:

• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

An allowed_vip_port block (within voltstack_cluster) supports the following:

• custom_ports - Optional String
Custom Ports. List of Custom port

• disable_allowed_vip_port - Optional Object
Enable this option

• use_http_https_port - Optional Object
Enable this option

• use_http_port - Optional Object
Enable this option

• use_https_port - Optional Object
Enable this option

Voltstack Cluster Allowed VIP Port Custom Ports

Section titled “Voltstack Cluster Allowed VIP Port Custom Ports”

A custom_ports block (within voltstack_cluster.allowed_vip_port) supports the following:

• port_ranges - Optional String
Port Ranges. Port Ranges

Voltstack Cluster Allowed VIP Port Disable Allowed VIP Port

Section titled “Voltstack Cluster Allowed VIP Port Disable Allowed VIP Port”

Deeply nested Port block collapsed for readability.

Voltstack Cluster Allowed VIP Port Use HTTP HTTPS Port

Section titled “Voltstack Cluster Allowed VIP Port Use HTTP HTTPS Port”

Deeply nested Port block collapsed for readability.

Voltstack Cluster Allowed VIP Port Use HTTP Port

Section titled “Voltstack Cluster Allowed VIP Port Use HTTP Port”

Deeply nested Port block collapsed for readability.

Voltstack Cluster Allowed VIP Port Use HTTPS Port

Section titled “Voltstack Cluster Allowed VIP Port Use HTTPS Port”

Deeply nested Port block collapsed for readability.

An az_nodes block (within voltstack_cluster) supports the following:

• aws_az_name - Optional String
AWS availability zone, must be consistent with the selected AWS region

• local_subnet - Optional String
Configuration parameter for local subnet

A local_subnet block (within voltstack_cluster.az_nodes) supports the following:

• existing_subnet_id - Optional String
Information about existing subnet ID

• subnet_param - Optional String
Parameters for creating a new cloud subnet

Voltstack Cluster Az Nodes Local Subnet Subnet Param

Section titled “Voltstack Cluster Az Nodes Local Subnet Subnet Param”

Deeply nested Param block collapsed for readability.

A dc_cluster_group block (within voltstack_cluster) supports the following:

• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

A default_storage block (within voltstack_cluster) supports the following:

A forward_proxy_allow_all block (within voltstack_cluster) supports the following:

A global_network_list block (within voltstack_cluster) supports the following:

• global_network_connections - Optional List
Global Network Connections. Global network connections

Voltstack Cluster Global Network List Global Network Connections

Section titled “Voltstack Cluster Global Network List Global Network Connections”

Deeply nested Connections block collapsed for readability.

Voltstack Cluster Global Network List Global Network Connections SLI To Global DR

Section titled “Voltstack Cluster Global Network List Global Network Connections SLI To Global DR”

Deeply nested DR block collapsed for readability.

Voltstack Cluster Global Network List Global Network Connections SLI To Global DR Global Vn

Section titled “Voltstack Cluster Global Network List Global Network Connections SLI To Global DR Global Vn”

Deeply nested Vn block collapsed for readability.

Voltstack Cluster Global Network List Global Network Connections Slo To Global DR

Section titled “Voltstack Cluster Global Network List Global Network Connections Slo To Global DR”

Deeply nested DR block collapsed for readability.

Voltstack Cluster Global Network List Global Network Connections Slo To Global DR Global Vn

Section titled “Voltstack Cluster Global Network List Global Network Connections Slo To Global DR Global Vn”

Deeply nested Vn block collapsed for readability.

A k8s_cluster block (within voltstack_cluster) supports the following:

• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name

• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace

• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant

A no_dc_cluster_group block (within voltstack_cluster) supports the following:

A no_forward_proxy block (within voltstack_cluster) supports the following:

A no_global_network block (within voltstack_cluster) supports the following:

A no_k8s_cluster block (within voltstack_cluster) supports the following:

A no_network_policy block (within voltstack_cluster) supports the following:

Voltstack Cluster No Outside Static Routes

Section titled “Voltstack Cluster No Outside Static Routes”

A no_outside_static_routes block (within voltstack_cluster) supports the following:

An outside_static_routes block (within voltstack_cluster) supports the following:

• static_route_list - Optional List
List of Static Routes. List of Static routes

Voltstack Cluster Outside Static Routes Static Route List

Section titled “Voltstack Cluster Outside Static Routes Static Route List”

Deeply nested List block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route”

Deeply nested Route block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Labels

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Labels”

Deeply nested Labels block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop”

Deeply nested Nexthop block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Interface

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Interface”

Deeply nested Interface block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address”

Deeply nested Address block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv4

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv4”

Deeply nested IPv4 block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv6

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Nexthop Nexthop Address IPv6”

Deeply nested IPv6 block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Subnets

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Subnets”

Deeply nested Subnets block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Subnets IPv4

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Subnets IPv4”

Deeply nested IPv4 block collapsed for readability.

Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Subnets IPv6

Section titled “Voltstack Cluster Outside Static Routes Static Route List Custom Static Route Subnets IPv6”

Deeply nested IPv6 block collapsed for readability.

A sm_connection_public_ip block (within voltstack_cluster) supports the following:

A sm_connection_pvt_ip block (within voltstack_cluster) supports the following:

A storage_class_list block (within voltstack_cluster) supports the following:

• storage_classes - Optional List
List of Storage Classes. List of custom storage classes

Voltstack Cluster Storage Class List Storage Classes

Section titled “Voltstack Cluster Storage Class List Storage Classes”

A storage_classes block (within voltstack_cluster.storage_class_list) supports the following:

• default_storage_class - Optional Bool
Make this storage class default storage class for the K8S cluster

• storage_class_name - Optional String
Name of the storage class as it will appear in K8S

A vpc block supports the following:

• new_vpc - Optional String
AWS VPC Parameters. Parameters to create new AWS VPC

• vpc_id - Optional String
Information about existing VPC ID

A new_vpc block (within vpc) supports the following:

• autogenerate - Optional Object
Configuration parameter for autogenerate

• name_tag - Optional String
Specify the VPC Name

• primary_ipv4 - Optional String
IPv4 CIDR block for this VPC. It has to be private address space. The Primary IPv4 block cannot be modified. All subnets prefixes in this VPC must be part of this CIDR block

An autogenerate block (within vpc.new_vpc) supports the following:


The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.

Object Reference {#common-object-reference}

Section titled “Object Reference {#common-object-reference}”

Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.

FieldTypeDescription
nameStringName of the referenced object
namespaceStringNamespace containing the referenced object
tenantStringTenant of the referenced object (system-managed)

Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.

ValueDescription
LOWER_CASEConvert to lowercase
UPPER_CASEConvert to uppercase
BASE64_DECODEDecodebase64 content
NORMALIZE_PATHNormalize URL path
REMOVE_WHITESPACERemove whitespace characters
URL_DECODEDecode URL-encoded characters
TRIM_LEFTTrim leading whitespace
TRIM_RIGHTTrim trailing whitespace
TRIMTrim both leading and trailing whitespace

HTTP methods used for request matching.

ValueDescription
ANYMatch any HTTP method
GETHTTP GET request
HEADHTTP HEAD request
POSTHTTP POST request
PUTHTTP PUT request
DELETEHTTP DELETE request
CONNECTHTTP CONNECT request
OPTIONSHTTP OPTIONS request
TRACEHTTP TRACE request
PATCHHTTP PATCH request
COPYHTTP COPY request (WebDAV)

TLS Fingerprints {#common-tls-fingerprints}

Section titled “TLS Fingerprints {#common-tls-fingerprints}”

TLS fingerprint categories for malicious client detection.

ValueDescription
TLS_FINGERPRINT_NONENo fingerprint matching
ANY_MALICIOUS_FINGERPRINTMatch any known malicious fingerprint
ADWAREAdware-associated fingerprints
DRIDEXDridex malware fingerprints
GOOTKITGootkit malware fingerprints
RANSOMWARERansomware-associated fingerprints
TRICKBOTTrickbot malware fingerprints

IP Threat Categories {#common-ip-threat-categories}

Section titled “IP Threat Categories {#common-ip-threat-categories}”

IP address threat categories for security filtering.

ValueDescription
SPAM_SOURCESKnown spam sources
WINDOWS_EXPLOITSWindows exploit sources
WEB_ATTACKSWeb attack sources
BOTNETSKnown botnet IPs
SCANNERSNetwork scanner IPs
REPUTATIONPoor reputation IPs
PHISHINGPhishing-related IPs
PROXYAnonymous proxy IPs
MOBILE_THREATSMobile threat sources
TOR_PROXYTor exit nodes
DENIAL_OF_SERVICEDoS attack sources
NETWORKKnown bad network ranges