- Home
- Documentation
- Load Balancing
- Data Sources
- xcsh_origin_pool (Data Source)
xcsh_origin_pool (Data Source)
Retrieves information about an Origin Pool resource in F5 Distributed Cloud for defining backend server pools for load balancer targets. This is a read-only data source.
~> Note: For more information, see the Origin Pool API documentation.
Example Usage
Section titled “Example Usage”# OriginPool Data Source Example
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Look up an existing OriginPool by namedata "xcsh_origin_pool" "example" { name = "example-origin-pool" namespace = "staging"}
output "origin_pool_id" { value = data.xcsh_origin_pool.example.id}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
Minimum Configuration
Section titled “Minimum Configuration”Required fields:
namenamespaceorigin_serversport
Example (API format):
apiVersion: v1kind: origin_poolmetadata: name: backend-pool namespace: demo-appspec: origin_servers: - public_name: dns_name: backend1.example.com - public_name: dns_name: backend2.example.com port: 8080Metadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the OriginPool
• namespace - Required String
Namespace where the OriginPool exists
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• advanced_options - Optional String Defaults to null
Configure Advanced OPTIONS for origin pool
• annotations - Optional Map
Annotations applied to this resource
• automatic_port - Optional Object
Enable this option
• description - Optional String
Description of the OriginPool
• endpoint_selection - Optional String Defaults to DISTRIBUTED
Possible values are DISTRIBUTED, LOCAL_ONLY, LOCAL_PREFERRED
[Enum: DISTRIBUTED|LOCAL_ONLY|LOCAL_PREFERRED] Policy for selection of endpoints from local site/remote site/both Consider both remote and local endpoints for load balancing LOCAL_ONLY: Consider
only local endpoints for load balancing Enable this policy to load balance ONLY among locally discovered endpoints Prefer the local endpoints for.. Server applies default when omitted
• health_check_port - Optional Number
Port used for performing health check
• healthcheck - Optional List Defaults to []
Reference to healthcheck configuration objects. Server applies default when omitted
• id - Optional String
Unique identifier for the resource
• labels - Optional Map
Labels applied to this resource
• lb_port - Optional Object
Enable this option
• loadbalancer_algorithm - Optional String Defaults to ROUND_ROBIN
Possible values are ROUND_ROBIN, LEAST_REQUEST, RING_HASH, RANDOM, LB_OVERRIDE
[Enum: ROUND_ROBIN|LEAST_REQUEST|RING_HASH|RANDOM|LB_OVERRIDE] Different load balancing algorithms supported When a connection to an endpoint in an upstream cluster
is required, the load balancer uses loadbalancer_algorithm to determine which host is selected. - ROUND_ROBIN: ROUND_ROBIN Policy in which each healthy/available upstream endpoint is selected in.. Server applies default when omitted
• no_tls - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• origin_servers - Optional List
Origin Servers. List of origin servers in this pool
• port - Optional Number
Endpoint service is available on this port. Recommended: 443
• same_as_endpoint_port - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• upstream_conn_pool_reuse_type - Optional String Defaults to null
Select upstream connection pool reuse state for every downstream connection. This configuration choice is for HTTP(S) LB only
• use_tls - Optional String
TLS Parameters for Origin Servers. Upstream TLS Parameters
• auto_http_config - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• circuit_breaker - Optional String
CircuitBreaker provides a mechanism for watching failures in upstream connections or requests and if the failures reach a certain threshold, automatically fail subsequent requests which allows to apply back pressure on downstream quickly
• connection_timeout - Optional Number Specified in milliseconds
The timeout for new network connections to endpoints in the cluster. The default value is 2 seconds. Recommended: 2000 ⚙️ Server Default
• default_circuit_breaker - Optional Object Defaults to map[]
Configuration parameter for default circuit breaker. Server applies default when omitted
• disable_circuit_breaker - Optional Object
Configuration parameter for disable circuit breaker
• disable_lb_source_ip_persistence - Optional Object
Enable this option
• disable_outlier_detection - Optional Object Defaults to map[]
Configuration parameter for disable outlier detection. Server applies default when omitted
• disable_proxy_protocol - Optional Object
Configuration parameter for disable proxy protocol
• disable_subsets - Optional Object Defaults to map[]
Configuration parameter for disable subsets. Server applies default when omitted
• enable_lb_source_ip_persistence - Optional Object
Enable this option
• enable_subsets - Optional String
Configure subset OPTIONS for origin pool
• http1_config - Optional String
HTTP/1.1 Protocol OPTIONS for upstream connections
• http2_options - Optional String
Http2 Protocol OPTIONS for upstream connections
• http_idle_timeout - Optional Number
The idle timeout for upstream connection pool connections. The idle timeout is defined as the period in which there are no active requests. When the idle timeout is reached the connection will be closed. Recommended: 300000 ⚙️ Server Default
• max_requests_per_connection - Optional Number
Sets the maximum number of requests allowed per connection to the origin server. Enter a value >=1 to define the request limit per connection
• no_panic_threshold - Optional Object Defaults to map[]
Configuration parameter for no panic threshold. Server applies default when omitted
• no_request_limit_per_connection - Optional Object Defaults to map[]
Configuration parameter for no request limit per connection. Server applies default when omitted
• outlier_detection - Optional String
Outlier detection and ejection is the process of dynamically determining whether some number of hosts in an upstream cluster are performing unlike the others and removing them from the healthy load balancing set. Outlier detection is a form of passive health checking. Algorithm 1
• panic_threshold - Optional Number
Configure a threshold (percentage of unhealthy endpoints) below which all endpoints will be considered for load balancing ignoring its health status
• proxy_protocol_v1 - Optional Object
Configuration parameter for proxy protocol v1
• proxy_protocol_v2 - Optional Object
Configuration parameter for proxy protocol v2
• connection_limit - Optional Number
The maximum number of connections that loadbalancer will establish to all hosts in an upstream cluster. In practice this is only applicable to TCP and HTTP/1.1 clusters since HTTP/2 uses a single connection to each host. Remove endpoint out of load balancing decision, if number of connections
• max_requests - Optional Number
The maximum number of requests that can be outstanding to all hosts in a cluster at any given time. In practice this is applicable to HTTP/2 clusters since HTTP/1.1 clusters are governed by the maximum connections (connection_limit). Remove endpoint out of load balancing decision, if requests
• pending_requests - Optional Number
The maximum number of requests that will be queued while waiting for a ready connection pool connection. Since HTTP/2 requests are sent over a single connection, this circuit breaker only comes into play as the initial connection is created, as requests will be multiplexed immediately
• priority - Optional String Defaults to DEFAULT
Possible values are DEFAULT, HIGH
[Enum: DEFAULT|HIGH] Priority routing for each request. Different connection pools are used based on the priority selected for the request. Also, circuit-breaker configuration at destination cluster is chosen based on selected priority
• retries - Optional Number
The maximum number of retries that can be outstanding to all hosts in a cluster at any given time. Remove endpoint out of load balancing decision, if retries for request exceed this count
• any_endpoint - Optional Object
Enable this option
• default_subset - Optional String
Configuration parameter for default subset
• endpoint_subsets - Optional List
List of subset class. Subsets class is defined using list of keys. Every unique combination of values of these keys form a subset within the class
• fail_request - Optional Object
Configuration parameter for fail request
• default_subset - Optional String
List of key-value pairs that define default subset. Which gets used when route specifies no metadata or no subset matching the metadata exists
• keys - Optional List
List of keys that define a cluster subset class
• header_transformation - Optional String
Header Transformation OPTIONS for HTTP/1.1 request/response headers
• default_header_transformation - Optional Object
Use the platform’s current default HTTP header transformation behavior
• preserve_case_header_transformation - Optional Object
Preserve HTTP header-name case when upstream case must remain unchanged
• proper_case_header_transformation - Optional Object
Transform HTTP header names to proper case when explicit transformation is required
• enabled - Optional Bool
Enable/disable HTTP2 Protocol for upstream connections
• base_ejection_time - Optional Number
The base time that a host is ejected for. The real time is equal to the base time multiplied by the number of times the host has been ejected. This causes hosts to GET ejected for longer periods if they continue to fail
• consecutive_5xx - Optional Number
If an upstream endpoint returns some number of consecutive 5xx, it will be ejected. Note that in this case a 5xx means an actual 5xx respond code, or an event that would cause the HTTP router to return one on the upstream’s behalf(reset, connection failure, etc.) consecutive_5xx indicates the
• consecutive_gateway_failure - Optional Number
If an upstream endpoint returns some number of consecutive “gateway errors” (502, 503 or 504 status code), it will be ejected. Note that this includes events that would cause the HTTP router to return one of these status codes on the upstream’s behalf (reset,
connection failure, etc.)
• interval - Optional Number Defaults to 10000ms
The time interval between ejection analysis sweeps. This can result in both new ejections as well as endpoints being returned to service
• max_ejection_percent - Optional Number Defaults to 10%
The maximum % of an upstream cluster that can be ejected due to outlier detection. but will eject at least one host regardless of the value
Healthcheck
Section titled “Healthcheck”A healthcheck block supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
LB Port
Section titled “LB Port”A lb_port block supports the following:
No TLS
Section titled “No TLS”A no_tls block supports the following:
Origin Servers
Section titled “Origin Servers”An origin_servers block supports the following:
• cbip_service - Optional String
Specify origin server with Classic BIG-IP Service (Virtual Server)
• consul_service - Optional String
Specify origin server with HashiCorp Consul service name and site information
• custom_endpoint_object - Optional String
Specify origin server with a reference to endpoint object
• k8s_service - Optional String
Specify origin server with K8S service name and site information
• labels - Optional Map
Add Labels for this origin server, these labels can be used to form subset
• private_ip - Optional String
Specify origin server with private or public IP address and site information
• private_name - Optional String
Specify origin server with private or public DNS name and site information
• public_ip - Optional String
Specify origin server with public IP address
• public_name - Optional String
Specify origin server with public DNS name
• vn_private_ip - Optional String
Specify origin server with IP on Virtual Network
• vn_private_name - Optional String
Specify origin server with DNS name on Virtual Network
Origin Servers Cbip Service
Section titled “Origin Servers Cbip Service”A cbip_service block (within origin_servers) supports the following:
• service_name - Optional String
Name of the discovered Classic BIG-IP virtual server to be used as origin
Origin Servers Consul Service
Section titled “Origin Servers Consul Service”A consul_service block (within origin_servers) supports the following:
• inside_network - Optional Object
Configuration parameter for inside network
• outside_network - Optional Object
Configuration parameter for outside network
• service_name - Optional String
Consul service name of this origin server will be listed, including cluster-ID. The format is servicename:cluster-ID
• site_locator - Optional String
Message defines a reference to a site or virtual site object
• snat_pool - Optional String
SNAT Pool. SNAT Pool configuration
Origin Servers Consul Service Inside Network
Section titled “Origin Servers Consul Service Inside Network”An inside_network block (within origin_servers.consul_service) supports the following:
Origin Servers Consul Service Outside Network
Section titled “Origin Servers Consul Service Outside Network”An outside_network block (within origin_servers.consul_service) supports the following:
Origin Servers Consul Service Site Locator
Section titled “Origin Servers Consul Service Site Locator”A site_locator block (within origin_servers.consul_service) supports the following:
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers Consul Service Site Locator Site
Section titled “Origin Servers Consul Service Site Locator Site”A site block (within origin_servers.consul_service.site_locator) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers Consul Service Site Locator Virtual Site
Section titled “Origin Servers Consul Service Site Locator Virtual Site”Deeply nested Site block collapsed for readability.
Origin Servers Consul Service Snat Pool
Section titled “Origin Servers Consul Service Snat Pool”A snat_pool block (within origin_servers.consul_service) supports the following:
• no_snat_pool - Optional Object
Configuration parameter for no snat pool
• snat_pool - Optional String
List of IPv4 prefixes that represent an endpoint
Origin Servers Consul Service Snat Pool No Snat Pool
Section titled “Origin Servers Consul Service Snat Pool No Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Consul Service Snat Pool Snat Pool
Section titled “Origin Servers Consul Service Snat Pool Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Custom Endpoint Object
Section titled “Origin Servers Custom Endpoint Object”A custom_endpoint_object block (within origin_servers) supports the following:
• endpoint - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers Custom Endpoint Object Endpoint
Section titled “Origin Servers Custom Endpoint Object Endpoint”An endpoint block (within origin_servers.custom_endpoint_object) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers K8S Service
Section titled “Origin Servers K8S Service”A k8s_service block (within origin_servers) supports the following:
• inside_network - Optional Object
Configuration parameter for inside network
• outside_network - Optional Object
Configuration parameter for outside network
• protocol - Optional String Defaults to PROTOCOL_TCP
Possible values are PROTOCOL_TCP, PROTOCOL_UDP
[Enum: PROTOCOL_TCP|PROTOCOL_UDP] Type of protocol - PROTOCOL_TCP: TCP - PROTOCOL_UDP: UDP
• service_name - Optional String
K8S service name of the origin server will be listed, including the namespace and cluster-ID. For vK8s services, you need to enter a string with the format servicename.namespace:example-namespace’frontend’, namespace is ‘speedtest’ and cluster-ID is ‘prod’, then you
will enter
• site_locator - Optional String
Message defines a reference to a site or virtual site object
• snat_pool - Optional String
SNAT Pool. SNAT Pool configuration
• vk8s_networks - Optional Object
Configuration parameter for vk8s networks
Origin Servers K8S Service Inside Network
Section titled “Origin Servers K8S Service Inside Network”An inside_network block (within origin_servers.k8s_service) supports the following:
Origin Servers K8S Service Outside Network
Section titled “Origin Servers K8S Service Outside Network”An outside_network block (within origin_servers.k8s_service) supports the following:
Origin Servers K8S Service Site Locator
Section titled “Origin Servers K8S Service Site Locator”A site_locator block (within origin_servers.k8s_service) supports the following:
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers K8S Service Site Locator Site
Section titled “Origin Servers K8S Service Site Locator Site”A site block (within origin_servers.k8s_service.site_locator) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers K8S Service Site Locator Virtual Site
Section titled “Origin Servers K8S Service Site Locator Virtual Site”Deeply nested Site block collapsed for readability.
Origin Servers K8S Service Snat Pool
Section titled “Origin Servers K8S Service Snat Pool”A snat_pool block (within origin_servers.k8s_service) supports the following:
• no_snat_pool - Optional Object
Configuration parameter for no snat pool
• snat_pool - Optional String
List of IPv4 prefixes that represent an endpoint
Origin Servers K8S Service Snat Pool No Snat Pool
Section titled “Origin Servers K8S Service Snat Pool No Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers K8S Service Snat Pool Snat Pool
Section titled “Origin Servers K8S Service Snat Pool Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers K8S Service Vk8s Networks
Section titled “Origin Servers K8S Service Vk8s Networks”A vk8s_networks block (within origin_servers.k8s_service) supports the following:
Origin Servers Private IP
Section titled “Origin Servers Private IP”A private_ip block (within origin_servers) supports the following:
• inside_network - Optional Object
Configuration parameter for inside network
• ip - Optional String
IP. Private IPv4 address
• outside_network - Optional Object
Configuration parameter for outside network
• segment - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• site_locator - Optional String
Message defines a reference to a site or virtual site object
• snat_pool - Optional String
SNAT Pool. SNAT Pool configuration
Origin Servers Private IP Inside Network
Section titled “Origin Servers Private IP Inside Network”An inside_network block (within origin_servers.private_ip) supports the following:
Origin Servers Private IP Outside Network
Section titled “Origin Servers Private IP Outside Network”An outside_network block (within origin_servers.private_ip) supports the following:
Origin Servers Private IP Segment
Section titled “Origin Servers Private IP Segment”A segment block (within origin_servers.private_ip) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers Private IP Site Locator
Section titled “Origin Servers Private IP Site Locator”A site_locator block (within origin_servers.private_ip) supports the following:
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers Private IP Site Locator Site
Section titled “Origin Servers Private IP Site Locator Site”A site block (within origin_servers.private_ip.site_locator) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers Private IP Site Locator Virtual Site
Section titled “Origin Servers Private IP Site Locator Virtual Site”Deeply nested Site block collapsed for readability.
Origin Servers Private IP Snat Pool
Section titled “Origin Servers Private IP Snat Pool”A snat_pool block (within origin_servers.private_ip) supports the following:
• no_snat_pool - Optional Object
Configuration parameter for no snat pool
• snat_pool - Optional String
List of IPv4 prefixes that represent an endpoint
Origin Servers Private IP Snat Pool No Snat Pool
Section titled “Origin Servers Private IP Snat Pool No Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Private IP Snat Pool Snat Pool
Section titled “Origin Servers Private IP Snat Pool Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Private Name
Section titled “Origin Servers Private Name”A private_name block (within origin_servers) supports the following:
• dns_name - Optional String
DNS Name. DNS Name
• inside_network - Optional Object
Configuration parameter for inside network
• outside_network - Optional Object
Configuration parameter for outside network
• refresh_interval - Optional Number
Interval for DNS refresh in seconds. Max value is 7 days as per HTTPS://datatracker.ietf.org/doc/HTML/rfc8767.
• segment - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• site_locator - Optional String
Message defines a reference to a site or virtual site object
• snat_pool - Optional String
SNAT Pool. SNAT Pool configuration
Origin Servers Private Name Inside Network
Section titled “Origin Servers Private Name Inside Network”An inside_network block (within origin_servers.private_name) supports the following:
Origin Servers Private Name Outside Network
Section titled “Origin Servers Private Name Outside Network”An outside_network block (within origin_servers.private_name) supports the following:
Origin Servers Private Name Segment
Section titled “Origin Servers Private Name Segment”A segment block (within origin_servers.private_name) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers Private Name Site Locator
Section titled “Origin Servers Private Name Site Locator”A site_locator block (within origin_servers.private_name) supports the following:
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers Private Name Site Locator Site
Section titled “Origin Servers Private Name Site Locator Site”A site block (within origin_servers.private_name.site_locator) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers Private Name Site Locator Virtual Site
Section titled “Origin Servers Private Name Site Locator Virtual Site”Deeply nested Site block collapsed for readability.
Origin Servers Private Name Snat Pool
Section titled “Origin Servers Private Name Snat Pool”A snat_pool block (within origin_servers.private_name) supports the following:
• no_snat_pool - Optional Object
Configuration parameter for no snat pool
• snat_pool - Optional String
List of IPv4 prefixes that represent an endpoint
Origin Servers Private Name Snat Pool No Snat Pool
Section titled “Origin Servers Private Name Snat Pool No Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Private Name Snat Pool Snat Pool
Section titled “Origin Servers Private Name Snat Pool Snat Pool”Deeply nested Pool block collapsed for readability.
Origin Servers Public IP
Section titled “Origin Servers Public IP”A public_ip block (within origin_servers) supports the following:
• ip - Optional String
Public IPv4. Public IPv4 address
Origin Servers Public Name
Section titled “Origin Servers Public Name”A public_name block (within origin_servers) supports the following:
• dns_name - Optional String
DNS Name. DNS Name
• refresh_interval - Optional Number
Interval for DNS refresh in seconds. Max value is 7 days as per HTTPS://datatracker.ietf.org/doc/HTML/rfc8767.
Origin Servers Vn Private IP
Section titled “Origin Servers Vn Private IP”A vn_private_ip block (within origin_servers) supports the following:
• ip - Optional String
IPv4. IPv4 address
• virtual_network - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers Vn Private IP Virtual Network
Section titled “Origin Servers Vn Private IP Virtual Network”A virtual_network block (within origin_servers.vn_private_ip) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Origin Servers Vn Private Name
Section titled “Origin Servers Vn Private Name”A vn_private_name block (within origin_servers) supports the following:
• dns_name - Optional String
DNS Name. DNS Name
• private_network - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
Origin Servers Vn Private Name Private Network
Section titled “Origin Servers Vn Private Name Private Network”A private_network block (within origin_servers.vn_private_name) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Same As Endpoint Port
Section titled “Same As Endpoint Port”A same_as_endpoint_port block supports the following:
Upstream Conn Pool Reuse Type
Section titled “Upstream Conn Pool Reuse Type”An upstream_conn_pool_reuse_type block supports the following:
• disable_conn_pool_reuse - Optional Object
Configuration parameter for disable conn pool reuse
• enable_conn_pool_reuse - Optional Object
Configuration parameter for enable conn pool reuse
Upstream Conn Pool Reuse Type Disable Conn Pool Reuse
Section titled “Upstream Conn Pool Reuse Type Disable Conn Pool Reuse”Deeply nested Reuse block collapsed for readability.
Upstream Conn Pool Reuse Type Enable Conn Pool Reuse
Section titled “Upstream Conn Pool Reuse Type Enable Conn Pool Reuse”Deeply nested Reuse block collapsed for readability.
Use TLS
Section titled “Use TLS”An use_tls block supports the following:
• default_session_key_caching - Optional Object Defaults to map[]
Configuration parameter for default session key caching. Server applies default when omitted
• disable_session_key_caching - Optional Object
Configuration parameter for disable session key caching
• disable_sni - Optional Object
Configuration parameter for disable sni
• max_session_keys - Optional Number
Number of session keys that are cached
• no_mtls - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• skip_server_verification - Optional Object
Enable this option
• sni - Optional String
SNI value to be used
• tls_config - Optional String
Defines various OPTIONS to configure TLS configuration parameters
• use_host_header_as_sni - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• use_mtls - Optional String
mTLS Certificate. mTLS Client Certificate
• use_mtls_obj - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• use_server_verification - Optional String
Configuration parameter for use server verification
• volterra_trusted_ca - Optional Object Defaults to map[]
Configuration parameter for volterra trusted CA. Server applies default when omitted
Use TLS Default Session Key Caching
Section titled “Use TLS Default Session Key Caching”A default_session_key_caching block (within use_tls) supports the following:
Use TLS Disable Session Key Caching
Section titled “Use TLS Disable Session Key Caching”A disable_session_key_caching block (within use_tls) supports the following:
Use TLS Disable Sni
Section titled “Use TLS Disable Sni”A disable_sni block (within use_tls) supports the following:
Use TLS No mTLS
Section titled “Use TLS No mTLS”A no_mtls block (within use_tls) supports the following:
Use TLS Skip Server Verification
Section titled “Use TLS Skip Server Verification”A skip_server_verification block (within use_tls) supports the following:
Use TLS TLS Config
Section titled “Use TLS TLS Config”A tls_config block (within use_tls) supports the following:
• custom_security - Optional String
Defines TLS protocol config including min/max versions and allowed ciphers
• default_security - Optional Object
Enable this option
• low_security - Optional Object
Enable this option
• medium_security - Optional Object
Enable this option
Use TLS TLS Config Custom Security
Section titled “Use TLS TLS Config Custom Security”A custom_security block (within use_tls.tls_config) supports the following:
• cipher_suites - Optional List
The TLS listener will only support the specified cipher list
• max_version - Optional String Defaults to TLS_AUTO
Possible values are TLS_AUTO, TLSv1_0, TLSv1_1, TLSv1_2, TLSv1_3
[Enum: TLS_AUTO|TLSv1_0|TLSv1_1|TLSv1_2|TLSv1_3] TlsProtocol is enumeration of supported TLS versions F5 Distributed Cloud will choose the optimal TLS version
• min_version - Optional String Defaults to TLS_AUTO
Possible values are TLS_AUTO, TLSv1_0, TLSv1_1, TLSv1_2, TLSv1_3
[Enum: TLS_AUTO|TLSv1_0|TLSv1_1|TLSv1_2|TLSv1_3] TlsProtocol is enumeration of supported TLS versions F5 Distributed Cloud will choose the optimal TLS version
Use TLS TLS Config Default Security
Section titled “Use TLS TLS Config Default Security”A default_security block (within use_tls.tls_config) supports the following:
Use TLS TLS Config Low Security
Section titled “Use TLS TLS Config Low Security”A low_security block (within use_tls.tls_config) supports the following:
Use TLS TLS Config Medium Security
Section titled “Use TLS TLS Config Medium Security”A medium_security block (within use_tls.tls_config) supports the following:
Use TLS Use Host Header As Sni
Section titled “Use TLS Use Host Header As Sni”An use_host_header_as_sni block (within use_tls) supports the following:
Use TLS Use mTLS
Section titled “Use TLS Use mTLS”An use_mtls block (within use_tls) supports the following:
• tls_certificates - Optional List
mTLS Client Certificate. mTLS Client Certificate
Use TLS Use mTLS TLS Certificates
Section titled “Use TLS Use mTLS TLS Certificates”A tls_certificates block (within use_tls.use_mtls) supports the following:
• certificate_url - Optional String
TLS certificate. Certificate or certificate chain in PEM format including the PEM headers
• custom_hash_algorithms - Optional String
Specifies the hash algorithms to be used
• description_spec - Optional String
Description. Description for the certificate
• disable_ocsp_stapling - Optional Object
Configuration parameter for disable OCSP stapling
• private_key - Optional String
SecretType is used in an object to indicate a sensitive/confidential field
• use_system_defaults - Optional Object
Configuration parameter for use system defaults
Use TLS Use mTLS TLS Certificates Custom Hash Algorithms
Section titled “Use TLS Use mTLS TLS Certificates Custom Hash Algorithms”Deeply nested Algorithms block collapsed for readability.
Use TLS Use mTLS TLS Certificates Disable OCSP Stapling
Section titled “Use TLS Use mTLS TLS Certificates Disable OCSP Stapling”Deeply nested Stapling block collapsed for readability.
Use TLS Use mTLS TLS Certificates Private Key
Section titled “Use TLS Use mTLS TLS Certificates Private Key”Deeply nested Key block collapsed for readability.
Use TLS Use mTLS TLS Certificates Private Key Blindfold Secret Info
Section titled “Use TLS Use mTLS TLS Certificates Private Key Blindfold Secret Info”Deeply nested Info block collapsed for readability.
Use TLS Use mTLS TLS Certificates Private Key Clear Secret Info
Section titled “Use TLS Use mTLS TLS Certificates Private Key Clear Secret Info”Deeply nested Info block collapsed for readability.
Use TLS Use mTLS TLS Certificates Use System Defaults
Section titled “Use TLS Use mTLS TLS Certificates Use System Defaults”Deeply nested Defaults block collapsed for readability.
Use TLS Use mTLS Obj
Section titled “Use TLS Use mTLS Obj”An use_mtls_obj block (within use_tls) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Use TLS Use Server Verification
Section titled “Use TLS Use Server Verification”An use_server_verification block (within use_tls) supports the following:
• trusted_ca - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• trusted_ca_url - Optional String
Upload a Root CA Certificate specifically for this Origin Pool for verification of server’s certificate
Use TLS Use Server Verification Trusted CA
Section titled “Use TLS Use Server Verification Trusted CA”A trusted_ca block (within use_tls.use_server_verification) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
Use TLS Volterra Trusted CA
Section titled “Use TLS Volterra Trusted CA”A volterra_trusted_ca block (within use_tls) supports the following:
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |