- Home
- Documentation
- DNS
- Data Sources
- xcsh_dns_proxy (Data Source)
xcsh_dns_proxy (Data Source)
Retrieves information about DNS Proxy in a given namespace. If one already exists it will give an error in F5 Distributed Cloud. This is a read-only data source.
~> Note: For more information, see the F5 Distributed Cloud API documentation.
Example Usage
Section titled “Example Usage”# DNSProxy Data Source Example
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Look up an existing DNSProxy by namedata "xcsh_dns_proxy" "example" { name = "example-dns-proxy" namespace = "system"}
output "dns_proxy_id" { value = data.xcsh_dns_proxy.example.id}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
Metadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the DNSProxy
• namespace - Optional String
Namespace where the DNSProxy exists
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• annotations - Optional Map
Annotations applied to this resource
• cache_profile - Optional String
DNS Cache specifies cache configuration
• ddos_profile - Optional String
Configuration parameter for DDOS profile
• description - Optional String
Description of the DNSProxy
• id - Optional String
Unique identifier for the resource
• irules - Optional List
OPTIONS for attaching iRules to DNS proxy
• labels - Optional Map
Labels applied to this resource
• lb_algorithm - Optional String
Configuration parameter for LB algorithm
• origin_servers - Optional String
List of origin Servers for the DNS proxy
• protocol_inspection - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• proxy_advertisement - Optional String
Configuration parameter for proxy advertisement
• transport_type - Optional String Defaults to UDP
Possible values are UDP, TCP, BothTCPAndUDP
[Enum: UDP|TCP|BothTCPAndUDP] Transport Type - UDP: UDP - TCP: TCP - BothTCPAndUDP: Both TCP and UDP
• cache_size - Optional Number
cache size
• disable_cache_profile - Optional Object
Configuration parameter for disable cache profile
• disable_ddos_mitigation - Optional Object
Enable this option
• enable_ddos_mitigation - Optional Object
Enable this option
Irules
Section titled “Irules”An irules block supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
LB Algorithm
Section titled “LB Algorithm”A lb_algorithm block supports the following:
• round_robin - Optional String
Configuration parameter for round robin
LB Algorithm Round Robin
Section titled “LB Algorithm Round Robin”A round_robin block (within lb_algorithm) supports the following:
Origin Servers
Section titled “Origin Servers”An origin_servers block supports the following:
• health_checks - Optional String
Configuration parameter for health checks
• origin_servers - Optional List
List Of Origin Servers. List of origin servers for Proxy
Origin Servers Health Checks
Section titled “Origin Servers Health Checks”A health_checks block (within origin_servers) supports the following:
• health_check - Optional List
List of Health Checks. List of Health Checks
• healthy_threshold - Optional Number
Number of successful responses before declaring healthy. In other words, this is the number of healthy health checks required before a host is marked healthy. Note that during startup, only a single successful health check is required to mark a host healthy
• interval - Optional Number
Time interval in seconds between two healthcheck requests
• timeout - Optional Number
Timeout in seconds to wait for successful response. In other words, it is the time to wait for a health check response. If the timeout is reached the health check attempt will be considered a failure
• unhealthy_threshold - Optional Number
Number of failed responses before declaring unhealthy. In other words, this is the number of unhealthy health checks required before a host is marked unhealthy. Note that for HTTP health checking if a host responds with 503 this threshold is ignored and
the host is considered unhealthy immediately
Origin Servers Health Checks Health Check
Section titled “Origin Servers Health Checks Health Check”A health_check block (within origin_servers.health_checks) supports the following:
• dns_health_check - Optional String
DNS health check reports healthy if DNS query is successful and response header and answer matches the given value
• icmp_health_check - Optional Object
Configuration parameter for ICMP health check
• tcp_health_check - Optional String
Monitor reports healthy status if UDP connection is successful and response payload matches expected response pattern
Origin Servers Health Checks Health Check DNS Health Check
Section titled “Origin Servers Health Checks Health Check DNS Health Check”Deeply nested Check block collapsed for readability.
Origin Servers Health Checks Health Check ICMP Health Check
Section titled “Origin Servers Health Checks Health Check ICMP Health Check”Deeply nested Check block collapsed for readability.
Origin Servers Health Checks Health Check TCP Health Check
Section titled “Origin Servers Health Checks Health Check TCP Health Check”Deeply nested Check block collapsed for readability.
Origin Servers Origin Servers
Section titled “Origin Servers Origin Servers”An origin_servers block (within origin_servers) supports the following:
• k8s_service - Optional String
Specify origin server with K8S service name and site information
• no_preference - Optional Object
Configuration parameter for no preference
• public_ip - Optional String
Specify origin server with public IP address
• public_name - Optional String
Specify origin server with public DNS name
• site_preferences - Optional String
Carries the references to one or more sites
Origin Servers Origin Servers K8S Service
Section titled “Origin Servers Origin Servers K8S Service”A k8s_service block (within origin_servers.origin_servers) supports the following:
• inside_network - Optional Object
Configuration parameter for inside network
• outside_network - Optional Object
Configuration parameter for outside network
• protocol - Optional String Defaults to PROTOCOL_TCP
Possible values are PROTOCOL_TCP, PROTOCOL_UDP
[Enum: PROTOCOL_TCP|PROTOCOL_UDP] Type of protocol - PROTOCOL_TCP: TCP - PROTOCOL_UDP: UDP
• service_name - Optional String
K8S service name of the origin server will be listed, including the namespace and cluster-ID. For vK8s services, you need to enter a string with the format servicename.namespace:example-namespace’frontend’, namespace is ‘speedtest’ and cluster-ID is ‘prod’, then you will enter
• site_locator - Optional String
Message defines a reference to a site or virtual site object
• snat_pool - Optional String
SNAT Pool. SNAT Pool configuration
• vk8s_networks - Optional Object
Configuration parameter for vk8s networks
Origin Servers Origin Servers K8S Service Inside Network
Section titled “Origin Servers Origin Servers K8S Service Inside Network”Deeply nested Network block collapsed for readability.
Origin Servers Origin Servers K8S Service Outside Network
Section titled “Origin Servers Origin Servers K8S Service Outside Network”Deeply nested Network block collapsed for readability.
Origin Servers Origin Servers K8S Service Site Locator
Section titled “Origin Servers Origin Servers K8S Service Site Locator”Deeply nested Locator block collapsed for readability.
Origin Servers Origin Servers K8S Service Site Locator Site
Section titled “Origin Servers Origin Servers K8S Service Site Locator Site”Deeply nested Site block collapsed for readability.
Origin Servers Origin Servers K8S Service Site Locator Virtual Site
Section titled “Origin Servers Origin Servers K8S Service Site Locator Virtual Site”Deeply nested Site block collapsed for readability.
Origin Servers Origin Servers K8S Service Snat Pool
Section titled “Origin Servers Origin Servers K8S Service Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Origin Servers K8S Service Snat Pool No Snat Pool
Section titled “Origin Servers Origin Servers K8S Service Snat Pool No Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Origin Servers K8S Service Snat Pool Snat Pool
Section titled “Origin Servers Origin Servers K8S Service Snat Pool Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Origin Servers K8S Service Vk8s Networks
Section titled “Origin Servers Origin Servers K8S Service Vk8s Networks”Deeply nested Networks block collapsed for readability.
Origin Servers Origin Servers No Preference
Section titled “Origin Servers Origin Servers No Preference”A no_preference block (within origin_servers.origin_servers) supports the following:
Origin Servers Origin Servers Public IP
Section titled “Origin Servers Origin Servers Public IP”A public_ip block (within origin_servers.origin_servers) supports the following:
• ip - Optional String
Public IPv4. Public IPv4 address
Origin Servers Origin Servers Public Name
Section titled “Origin Servers Origin Servers Public Name”A public_name block (within origin_servers.origin_servers) supports the following:
• dns_name - Optional String
DNS Name. DNS Name
• refresh_interval - Optional Number
Interval for DNS refresh in seconds. Max value is 7 days as per HTTPS://datatracker.ietf.org/doc/HTML/rfc8767.
Origin Servers Origin Servers Site Preferences
Section titled “Origin Servers Origin Servers Site Preferences”A site_preferences block (within origin_servers.origin_servers) supports the following:
• refs - Optional List
Site References. Reference to one or more sites
Origin Servers Origin Servers Site Preferences Refs
Section titled “Origin Servers Origin Servers Site Preferences Refs”A refs block (within origin_servers.origin_servers.site_preferences) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Protocol Inspection
Section titled “Protocol Inspection”A protocol_inspection block supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Proxy Advertisement
Section titled “Proxy Advertisement”A proxy_advertisement block supports the following:
• advertise_custom - Optional String
Defines a way to advertise a VIP on specific sites
• advertise_on_public - Optional String
Defines a way to advertise a load balancer on public. If optional public_ip is provided, it will only be advertised on RE sites where that public_ip is available
• advertise_on_public_default_vip - Optional Object
Enable this option
• do_not_advertise - Optional Object
Configuration parameter for do not advertise
Proxy Advertisement Advertise Custom
Section titled “Proxy Advertisement Advertise Custom”An advertise_custom block (within proxy_advertisement) supports the following:
• advertise_where - Optional List
Where should this load balancer be available
Proxy Advertisement Advertise Custom Advertise Where
Section titled “Proxy Advertisement Advertise Custom Advertise Where”An advertise_where block (within proxy_advertisement.advertise_custom) supports the following:
• advertise_on_public - Optional String
Defines a way to advertise a load balancer on public. If optional public_ip is provided, it will only be advertised on RE sites where that public_ip is available
• port - Optional Number
Port to Listen
• port_ranges - Optional String
A string containing a comma separated list of port ranges. Each port range consists of a single port or two ports separated by ’-’
• site - Optional String
Defines a reference to a CE site along with network type and an optional IP address where a load balancer could be advertised
• use_default_port - Optional Object
Enable this option
• virtual_network - Optional String
Parameters to advertise on a given virtual network
• virtual_site - Optional String
Defines a reference to a customer site virtual site along with network type where a load balancer could be advertised
• virtual_site_with_vip - Optional String
Defines a reference to a customer site virtual site along with network type and IP where a load balancer could be advertised
• vk8s_service - Optional String
Defines a reference to a RE site or virtual site where a load balancer could be advertised in the vK8s service network
Proxy Advertisement Advertise Custom Advertise Where Advertise On Public
Section titled “Proxy Advertisement Advertise Custom Advertise Where Advertise On Public”Deeply nested Public block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Advertise On Public Public IP
Section titled “Proxy Advertisement Advertise Custom Advertise Where Advertise On Public Public IP”Deeply nested IP block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Site”A site block (within proxy_advertisement.advertise_custom.advertise_where) supports the following:
• ip - Optional String
Use given IP address as VIP on the site
• network - Optional String Defaults to SITE_NETWORK_INSIDE_AND_OUTSIDE
Possible values are SITE_NETWORK_INSIDE_AND_OUTSIDE, SITE_NETWORK_INSIDE, SITE_NETWORK_OUTSIDE, SITE_NETWORK_SERVICE, SITE_NETWORK_OUTSIDE_WITH_INTERNET_VIP, SITE_NETWORK_INSIDE_AND_OUTSIDE_WITH_INTERNET_VIP,
SITE_NETWORK_IP_FABRIC
[Enum: SITE_NETWORK_INSIDE_AND_OUTSIDE|SITE_NETWORK_INSIDE|SITE_NETWORK_OUTSIDE|SITE_NETWORK_SERVICE|SITE_NETWORK_OUTSIDE_WITH_INTERNET_VIP|SITE_NETWORK_INSIDE_AND_OUTSIDE_WITH_INTERNET_VIP|SITE_NETWORK_IP_FABRIC] Defines network types to be used on site All inside and outside networks. All inside and outside networks with internet VIP support. All inside networks
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Proxy Advertisement Advertise Custom Advertise Where Site Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Site Site”Deeply nested Site block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Use Default Port
Section titled “Proxy Advertisement Advertise Custom Advertise Where Use Default Port”Deeply nested Port block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Network
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Network”Deeply nested Network block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Network Default V6 VIP
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Network Default V6 VIP”Deeply nested VIP block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Network Default VIP
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Network Default VIP”Deeply nested VIP block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Network Virtual Network
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Network Virtual Network”Deeply nested Network block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Site”Deeply nested Site block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Site Virtual Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Site Virtual Site”Deeply nested Site block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Site With VIP
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Site With VIP”Deeply nested VIP block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Virtual Site With VIP Virtual Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Virtual Site With VIP Virtual Site”Deeply nested Site block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Vk8s Service
Section titled “Proxy Advertisement Advertise Custom Advertise Where Vk8s Service”Deeply nested Service block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Vk8s Service Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Vk8s Service Site”Deeply nested Site block collapsed for readability.
Proxy Advertisement Advertise Custom Advertise Where Vk8s Service Virtual Site
Section titled “Proxy Advertisement Advertise Custom Advertise Where Vk8s Service Virtual Site”Deeply nested Site block collapsed for readability.
Proxy Advertisement Advertise On Public
Section titled “Proxy Advertisement Advertise On Public”An advertise_on_public block (within proxy_advertisement) supports the following:
• public_ip - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Proxy Advertisement Advertise On Public Public IP
Section titled “Proxy Advertisement Advertise On Public Public IP”A public_ip block (within proxy_advertisement.advertise_on_public) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Proxy Advertisement Advertise On Public Default VIP
Section titled “Proxy Advertisement Advertise On Public Default VIP”An advertise_on_public_default_vip block (within proxy_advertisement) supports the following:
Proxy Advertisement Do Not Advertise
Section titled “Proxy Advertisement Do Not Advertise”A do_not_advertise block (within proxy_advertisement) supports the following:
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |