- Home
- Documentation
- Load Balancing
- Data Sources
- xcsh_tcp_loadbalancer (Data Source)
xcsh_tcp_loadbalancer (Data Source)
Retrieves information about a TCP Load Balancer resource in F5 Distributed Cloud for load balancing TCP traffic across origin pools. This is a read-only data source.
~> Note: For more information, see the TCP Loadbalancer API documentation.
Example Usage
Section titled “Example Usage”# TCPLoadBalancer Data Source Example
terraform { required_version = ">= 1.0"
required_providers { xcsh = { source = "f5-sales-demo/xcsh" version = ">= 0.1.0" } }}
# Look up an existing TCPLoadBalancer by namedata "xcsh_tcp_loadbalancer" "example" { name = "example-tcp-loadbalancer" namespace = "staging"}
output "tcp_loadbalancer_id" { value = data.xcsh_tcp_loadbalancer.example.id}Argument Reference
Section titled “Argument Reference”-> Syntax Rule: This provider uses OneOf groups for mutually exclusive options. Fields documented as “Optional Block” use block syntax field_name { ... }. Empty OneOf object attributes use field_name = {}; conditional selection uses condition ? {} : null. Boolean attributes (such as add_hsts and http_redirect) use = true or = false.
🔶 High Risk Operations — Some operations on this resource have high danger level. Destructive operations may require confirmation.
~> Dependencies — This resource requires: origin_pool.
Minimum Configuration
Section titled “Minimum Configuration”Required fields:
namenamespaceorigin_pools
Example (API format):
apiVersion: v1kind: tcp_loadbalancermetadata: name: database-lb namespace: demo-appspec: listener: port: 5432 protocol: "TCP" origin_pools: - pool_name: postgres-cluster advertise: - public_ip: trueMetadata Argument Reference
Section titled “Metadata Argument Reference”• name - Required String
Name of the TCPLoadBalancer
• namespace - Required String
Namespace where the TCPLoadBalancer exists
Attributes Reference
Section titled “Attributes Reference”In addition to all arguments above, the following attributes are exported:
• active_service_policies - Optional String
Configuration parameter for active service policies
• advertise_custom - Optional String
Defines a way to advertise a VIP on specific sites
• advertise_on_public - Optional String
Defines a way to advertise a load balancer on public. If optional public_ip is provided, it will only be advertised on RE sites where that public_ip is available
• advertise_on_public_default_vip - Optional Object
Enable this option
• annotations - Optional Map
Annotations applied to this resource
• default_lb_with_sni - Optional Object
Configuration parameter for default LB with sni
• description - Optional String
Description of the TCPLoadBalancer
• dns_volterra_managed - Optional Bool Defaults to false
DNS records for domains will be managed automatically by F5 Distributed Cloud. This requires the domain to be delegated to F5XC using the Delegated Domain feature. Server applies default when omitted
• do_not_advertise - Optional Object
Configuration parameter for do not advertise
• do_not_retract_cluster - Optional Object
Enable this option
• domains - Optional List
List of Domains (host/authority header) that will be matched to this Load Balancer. Supported Domains and search order: 1. Exact Domain names: www.example.com. 2
• hash_policy_choice_least_active - Optional Object
Enable this option
• hash_policy_choice_random - Optional Object
Configuration parameter for hash policy choice random
• hash_policy_choice_round_robin - Optional Object Defaults to map[]
Configuration parameter for hash policy choice round robin. Server applies default when omitted
• hash_policy_choice_source_ip_stickiness - Optional Object
Enable this option
• id - Optional String
Unique identifier for the resource
• idle_timeout - Optional Number
The amount of time that a stream can exist without upstream or downstream activity, in milliseconds. Server applies default when omitted
• labels - Optional Map
Labels applied to this resource
• listen_port - Optional Number
Listen Port for this load balancer
• no_service_policies - Optional Object
Configuration parameter for no service policies
• no_sni - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• origin_pools_weights - Optional List
Origin pools and weights used for this load balancer
• port_ranges - Optional String
A string containing a comma separated list of port ranges. Each port range consists of a single port or two ports separated by ’-’
• retract_cluster - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• service_policies_from_namespace - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• sni - Optional Object
Enable this option
• tcp - Optional Object Defaults to map[]
Enable this option. Server applies default when omitted
• tls_tcp - Optional String
Choice for selecting TLS over TCP proxy with bring your own certificates
• tls_tcp_auto_cert - Optional String
Choice for selecting TLS over TCP proxy with automatic certificates
• policies - Optional List
Service Policies is a sequential engine where policies (and rules within the policy) are evaluated one after the other. It’s important to define the correct order (policies evaluated from top to bottom in the list) for service policies, to GET the intended result. For each request, its
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• advertise_where - Optional List
Where should this load balancer be available
• advertise_on_public - Optional String
Defines a way to advertise a load balancer on public. If optional public_ip is provided, it will only be advertised on RE sites where that public_ip is available
• port - Optional Number
Port to Listen
• port_ranges - Optional String
A string containing a comma separated list of port ranges. Each port range consists of a single port or two ports separated by ’-’
• site - Optional String
Defines a reference to a CE site along with network type and an optional IP address where a load balancer could be advertised
• use_default_port - Optional Object
Enable this option
• virtual_network - Optional String
Parameters to advertise on a given virtual network
• virtual_site - Optional String
Defines a reference to a customer site virtual site along with network type where a load balancer could be advertised
• virtual_site_with_vip - Optional String
Defines a reference to a customer site virtual site along with network type and IP where a load balancer could be advertised
• vk8s_service - Optional String
Defines a reference to a RE site or virtual site where a load balancer could be advertised in the vK8s service network
• public_ip - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• ip - Optional String
Use given IP address as VIP on the site
• network - Optional String Defaults to SITE_NETWORK_INSIDE_AND_OUTSIDE
Possible values are SITE_NETWORK_INSIDE_AND_OUTSIDE, SITE_NETWORK_INSIDE, SITE_NETWORK_OUTSIDE, SITE_NETWORK_SERVICE, SITE_NETWORK_OUTSIDE_WITH_INTERNET_VIP, SITE_NETWORK_INSIDE_AND_OUTSIDE_WITH_INTERNET_VIP, SITE_NETWORK_IP_FABRIC
[Enum:
SITE_NETWORK_INSIDE_AND_OUTSIDE|SITE_NETWORK_INSIDE|SITE_NETWORK_OUTSIDE|SITE_NETWORK_SERVICE|SITE_NETWORK_OUTSIDE_WITH_INTERNET_VIP|SITE_NETWORK_INSIDE_AND_OUTSIDE_WITH_INTERNET_VIP|SITE_NETWORK_IP_FABRIC] Defines network types to be used on site All inside and outside networks. All inside and outside networks with internet VIP support. All inside networks
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• default_v6_vip - Optional Object
Enable this option
• default_vip - Optional Object
Enable this option
• specific_v6_vip - Optional String
Use given IPv6 address as VIP on virtual Network
• specific_vip - Optional String
Use given IPv4 address as VIP on virtual Network
• virtual_network - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• network - Optional String Defaults to SITE_NETWORK_INSIDE_AND_OUTSIDE
Possible values are SITE_NETWORK_INSIDE_AND_OUTSIDE, SITE_NETWORK_INSIDE, SITE_NETWORK_OUTSIDE, SITE_NETWORK_SERVICE, SITE_NETWORK_OUTSIDE_WITH_INTERNET_VIP, SITE_NETWORK_INSIDE_AND_OUTSIDE_WITH_INTERNET_VIP, SITE_NETWORK_IP_FABRIC
[Enum:
SITE_NETWORK_INSIDE_AND_OUTSIDE|SITE_NETWORK_INSIDE|SITE_NETWORK_OUTSIDE|SITE_NETWORK_SERVICE|SITE_NETWORK_OUTSIDE_WITH_INTERNET_VIP|SITE_NETWORK_INSIDE_AND_OUTSIDE_WITH_INTERNET_VIP|SITE_NETWORK_IP_FABRIC] Defines network types to be used on site All inside and outside networks. All inside and outside networks with internet VIP support. All inside networks
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• ip - Optional String
Use given IP address as VIP on the site
• network - Optional String Defaults to SITE_NETWORK_SPECIFIED_VIP_OUTSIDE
Possible values are SITE_NETWORK_SPECIFIED_VIP_OUTSIDE, SITE_NETWORK_SPECIFIED_VIP_INSIDE
[Enum: SITE_NETWORK_SPECIFIED_VIP_OUTSIDE|SITE_NETWORK_SPECIFIED_VIP_INSIDE] Defines network types to be used on virtual-site with specified VIP All outside networks. All inside
networks
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• virtual_site - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• public_ip - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• cluster - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• endpoint_subsets - Optional String
Upstream origin pool may be configured to divide its origin servers into subsets based on metadata attached to the origin servers. Routes may then specify the metadata that an endpoint must match in order to be selected by the load balancer For origin servers which are discovered in K8S or Consul
• pool - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• priority - Optional Number
Priority of this origin pool, valid only with multiple origin pools. Value of 0 will make the pool as lowest priority origin pool Priority of 1 means highest priority and is considered active. When active origin pool is not available, lower priority origin pools are made active as per the
• weight - Optional Number
Weight of this origin pool, valid only with multiple origin pool. Value of 0 will disable the pool
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
A tcp block supports the following:
TLS TCP
Section titled “TLS TCP”A tls_tcp block supports the following:
• tls_cert_params - Optional String
Configuration parameter for TLS cert params
• tls_parameters - Optional String
Configuration parameter for TLS parameters
TLS TCP TLS Cert Params
Section titled “TLS TCP TLS Cert Params”A tls_cert_params block (within tls_tcp) supports the following:
• certificates - Optional List
Select one or more certificates with any domain names
• no_mtls - Optional Object
Enable this option
• tls_config - Optional String
Defines various OPTIONS to configure TLS configuration parameters
• use_mtls - Optional String
Validation context for downstream client TLS connections
TLS TCP TLS Cert Params Certificates
Section titled “TLS TCP TLS Cert Params Certificates”A certificates block (within tls_tcp.tls_cert_params) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
TLS TCP TLS Cert Params No mTLS
Section titled “TLS TCP TLS Cert Params No mTLS”A no_mtls block (within tls_tcp.tls_cert_params) supports the following:
TLS TCP TLS Cert Params TLS Config
Section titled “TLS TCP TLS Cert Params TLS Config”A tls_config block (within tls_tcp.tls_cert_params) supports the following:
• custom_security - Optional String
Defines TLS protocol config including min/max versions and allowed ciphers
• default_security - Optional Object
Enable this option
• low_security - Optional Object
Enable this option
• medium_security - Optional Object
Enable this option
TLS TCP TLS Cert Params TLS Config Custom Security
Section titled “TLS TCP TLS Cert Params TLS Config Custom Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Cert Params TLS Config Default Security
Section titled “TLS TCP TLS Cert Params TLS Config Default Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Cert Params TLS Config Low Security
Section titled “TLS TCP TLS Cert Params TLS Config Low Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Cert Params TLS Config Medium Security
Section titled “TLS TCP TLS Cert Params TLS Config Medium Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Cert Params Use mTLS
Section titled “TLS TCP TLS Cert Params Use mTLS”An use_mtls block (within tls_tcp.tls_cert_params) supports the following:
• client_certificate_optional - Optional Bool
Client certificate is optional. If the client has provided a certificate, the load balancer will verify it. If certification verification fails, the connection will be terminated
• crl - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• no_crl - Optional Object
Enable this option
• trusted_ca - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• trusted_ca_url - Optional String
Upload a Root CA Certificate specifically for this Load Balancer
• xfcc_disabled - Optional Object
Enable this option
• xfcc_options - Optional String
X-Forwarded-Client-Cert header elements to be added to requests
TLS TCP TLS Cert Params Use mTLS CRL
Section titled “TLS TCP TLS Cert Params Use mTLS CRL”Deeply nested CRL block collapsed for readability.
TLS TCP TLS Cert Params Use mTLS No CRL
Section titled “TLS TCP TLS Cert Params Use mTLS No CRL”Deeply nested CRL block collapsed for readability.
TLS TCP TLS Cert Params Use mTLS Trusted CA
Section titled “TLS TCP TLS Cert Params Use mTLS Trusted CA”Deeply nested CA block collapsed for readability.
TLS TCP TLS Cert Params Use mTLS Xfcc Disabled
Section titled “TLS TCP TLS Cert Params Use mTLS Xfcc Disabled”Deeply nested Disabled block collapsed for readability.
TLS TCP TLS Cert Params Use mTLS Xfcc Options
Section titled “TLS TCP TLS Cert Params Use mTLS Xfcc Options”Deeply nested Options block collapsed for readability.
TLS TCP TLS Parameters
Section titled “TLS TCP TLS Parameters”A tls_parameters block (within tls_tcp) supports the following:
• no_mtls - Optional Object
Enable this option
• tls_certificates - Optional List
Users can add one or more certificates that share the same set of domains. For example, domain.com and *.domain.com - but use different signature algorithms
• tls_config - Optional String
Defines various OPTIONS to configure TLS configuration parameters
• use_mtls - Optional String
Validation context for downstream client TLS connections
TLS TCP TLS Parameters No mTLS
Section titled “TLS TCP TLS Parameters No mTLS”A no_mtls block (within tls_tcp.tls_parameters) supports the following:
TLS TCP TLS Parameters TLS Certificates
Section titled “TLS TCP TLS Parameters TLS Certificates”A tls_certificates block (within tls_tcp.tls_parameters) supports the following:
• certificate_url - Optional String
TLS certificate. Certificate or certificate chain in PEM format including the PEM headers
• custom_hash_algorithms - Optional String
Specifies the hash algorithms to be used
• description_spec - Optional String
Description. Description for the certificate
• disable_ocsp_stapling - Optional Object
Configuration parameter for disable OCSP stapling
• private_key - Optional String
SecretType is used in an object to indicate a sensitive/confidential field
• use_system_defaults - Optional Object
Configuration parameter for use system defaults
TLS TCP TLS Parameters TLS Certificates Custom Hash Algorithms
Section titled “TLS TCP TLS Parameters TLS Certificates Custom Hash Algorithms”Deeply nested Algorithms block collapsed for readability.
TLS TCP TLS Parameters TLS Certificates Disable OCSP Stapling
Section titled “TLS TCP TLS Parameters TLS Certificates Disable OCSP Stapling”Deeply nested Stapling block collapsed for readability.
TLS TCP TLS Parameters TLS Certificates Private Key
Section titled “TLS TCP TLS Parameters TLS Certificates Private Key”Deeply nested Key block collapsed for readability.
TLS TCP TLS Parameters TLS Certificates Private Key Blindfold Secret Info
Section titled “TLS TCP TLS Parameters TLS Certificates Private Key Blindfold Secret Info”Deeply nested Info block collapsed for readability.
TLS TCP TLS Parameters TLS Certificates Private Key Clear Secret Info
Section titled “TLS TCP TLS Parameters TLS Certificates Private Key Clear Secret Info”Deeply nested Info block collapsed for readability.
TLS TCP TLS Parameters TLS Certificates Use System Defaults
Section titled “TLS TCP TLS Parameters TLS Certificates Use System Defaults”Deeply nested Defaults block collapsed for readability.
TLS TCP TLS Parameters TLS Config
Section titled “TLS TCP TLS Parameters TLS Config”A tls_config block (within tls_tcp.tls_parameters) supports the following:
• custom_security - Optional String
Defines TLS protocol config including min/max versions and allowed ciphers
• default_security - Optional Object
Enable this option
• low_security - Optional Object
Enable this option
• medium_security - Optional Object
Enable this option
TLS TCP TLS Parameters TLS Config Custom Security
Section titled “TLS TCP TLS Parameters TLS Config Custom Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Parameters TLS Config Default Security
Section titled “TLS TCP TLS Parameters TLS Config Default Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Parameters TLS Config Low Security
Section titled “TLS TCP TLS Parameters TLS Config Low Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Parameters TLS Config Medium Security
Section titled “TLS TCP TLS Parameters TLS Config Medium Security”Deeply nested Security block collapsed for readability.
TLS TCP TLS Parameters Use mTLS
Section titled “TLS TCP TLS Parameters Use mTLS”An use_mtls block (within tls_tcp.tls_parameters) supports the following:
• client_certificate_optional - Optional Bool
Client certificate is optional. If the client has provided a certificate, the load balancer will verify it. If certification verification fails, the connection will be terminated
• crl - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• no_crl - Optional Object
Enable this option
• trusted_ca - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• trusted_ca_url - Optional String
Upload a Root CA Certificate specifically for this Load Balancer
• xfcc_disabled - Optional Object
Enable this option
• xfcc_options - Optional String
X-Forwarded-Client-Cert header elements to be added to requests
TLS TCP TLS Parameters Use mTLS CRL
Section titled “TLS TCP TLS Parameters Use mTLS CRL”A crl block (within tls_tcp.tls_parameters.use_mtls) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
TLS TCP TLS Parameters Use mTLS No CRL
Section titled “TLS TCP TLS Parameters Use mTLS No CRL”Deeply nested CRL block collapsed for readability.
TLS TCP TLS Parameters Use mTLS Trusted CA
Section titled “TLS TCP TLS Parameters Use mTLS Trusted CA”Deeply nested CA block collapsed for readability.
TLS TCP TLS Parameters Use mTLS Xfcc Disabled
Section titled “TLS TCP TLS Parameters Use mTLS Xfcc Disabled”Deeply nested Disabled block collapsed for readability.
TLS TCP TLS Parameters Use mTLS Xfcc Options
Section titled “TLS TCP TLS Parameters Use mTLS Xfcc Options”Deeply nested Options block collapsed for readability.
TLS TCP Auto Cert
Section titled “TLS TCP Auto Cert”A tls_tcp_auto_cert block supports the following:
• no_mtls - Optional Object
Enable this option
• tls_config - Optional String
Defines various OPTIONS to configure TLS configuration parameters
• use_mtls - Optional String
Validation context for downstream client TLS connections
TLS TCP Auto Cert No mTLS
Section titled “TLS TCP Auto Cert No mTLS”A no_mtls block (within tls_tcp_auto_cert) supports the following:
TLS TCP Auto Cert TLS Config
Section titled “TLS TCP Auto Cert TLS Config”A tls_config block (within tls_tcp_auto_cert) supports the following:
• custom_security - Optional String
Defines TLS protocol config including min/max versions and allowed ciphers
• default_security - Optional Object
Enable this option
• low_security - Optional Object
Enable this option
• medium_security - Optional Object
Enable this option
TLS TCP Auto Cert TLS Config Custom Security
Section titled “TLS TCP Auto Cert TLS Config Custom Security”Deeply nested Security block collapsed for readability.
TLS TCP Auto Cert TLS Config Default Security
Section titled “TLS TCP Auto Cert TLS Config Default Security”Deeply nested Security block collapsed for readability.
TLS TCP Auto Cert TLS Config Low Security
Section titled “TLS TCP Auto Cert TLS Config Low Security”Deeply nested Security block collapsed for readability.
TLS TCP Auto Cert TLS Config Medium Security
Section titled “TLS TCP Auto Cert TLS Config Medium Security”Deeply nested Security block collapsed for readability.
TLS TCP Auto Cert Use mTLS
Section titled “TLS TCP Auto Cert Use mTLS”An use_mtls block (within tls_tcp_auto_cert) supports the following:
• client_certificate_optional - Optional Bool
Client certificate is optional. If the client has provided a certificate, the load balancer will verify it. If certification verification fails, the connection will be terminated
• crl - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• no_crl - Optional Object
Enable this option
• trusted_ca - Optional String
Type establishes a direct reference from one object(the referrer) to another(the referred). Such a reference is in form of tenant/namespace/name
• trusted_ca_url - Optional String
Upload a Root CA Certificate specifically for this Load Balancer
• xfcc_disabled - Optional Object
Enable this option
• xfcc_options - Optional String
X-Forwarded-Client-Cert header elements to be added to requests
TLS TCP Auto Cert Use mTLS CRL
Section titled “TLS TCP Auto Cert Use mTLS CRL”A crl block (within tls_tcp_auto_cert.use_mtls) supports the following:
• name - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then name will hold the referred object’s(e.g. Route’s) name
• namespace - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then namespace will hold the referred object’s(e.g. Route’s) namespace
• tenant - Optional String
When a configuration object(e.g. Virtual_host) refers to another(e.g route) then tenant will hold the referred object’s(e.g. Route’s) tenant
TLS TCP Auto Cert Use mTLS No CRL
Section titled “TLS TCP Auto Cert Use mTLS No CRL”Deeply nested CRL block collapsed for readability.
TLS TCP Auto Cert Use mTLS Trusted CA
Section titled “TLS TCP Auto Cert Use mTLS Trusted CA”Deeply nested CA block collapsed for readability.
TLS TCP Auto Cert Use mTLS Xfcc Disabled
Section titled “TLS TCP Auto Cert Use mTLS Xfcc Disabled”Deeply nested Disabled block collapsed for readability.
TLS TCP Auto Cert Use mTLS Xfcc Options
Section titled “TLS TCP Auto Cert Use mTLS Xfcc Options”Deeply nested Options block collapsed for readability.
Common Types
Section titled “Common Types”The following type definitions are used throughout this resource. See the full definition here rather than repeated inline.
Object Reference {#common-object-reference}
Section titled “Object Reference {#common-object-reference}”Object references establish a direct reference from one configuration object to another in F5 Distributed Cloud. References use the format tenant/namespace/name.
| Field | Type | Description |
|---|---|---|
name | String | Name of the referenced object |
namespace | String | Namespace containing the referenced object |
tenant | String | Tenant of the referenced object (system-managed) |
Transformers {#common-transformers}
Section titled “Transformers {#common-transformers}”Transformers apply transformations to input values before matching. Multiple transformers can be applied in order.
| Value | Description |
|---|---|
LOWER_CASE | Convert to lowercase |
UPPER_CASE | Convert to uppercase |
BASE64_DECODE | Decodebase64 content |
NORMALIZE_PATH | Normalize URL path |
REMOVE_WHITESPACE | Remove whitespace characters |
URL_DECODE | Decode URL-encoded characters |
TRIM_LEFT | Trim leading whitespace |
TRIM_RIGHT | Trim trailing whitespace |
TRIM | Trim both leading and trailing whitespace |
HTTP Methods {#common-http-methods}
Section titled “HTTP Methods {#common-http-methods}”HTTP methods used for request matching.
| Value | Description |
|---|---|
ANY | Match any HTTP method |
GET | HTTP GET request |
HEAD | HTTP HEAD request |
POST | HTTP POST request |
PUT | HTTP PUT request |
DELETE | HTTP DELETE request |
CONNECT | HTTP CONNECT request |
OPTIONS | HTTP OPTIONS request |
TRACE | HTTP TRACE request |
PATCH | HTTP PATCH request |
COPY | HTTP COPY request (WebDAV) |
TLS Fingerprints {#common-tls-fingerprints}
Section titled “TLS Fingerprints {#common-tls-fingerprints}”TLS fingerprint categories for malicious client detection.
| Value | Description |
|---|---|
TLS_FINGERPRINT_NONE | No fingerprint matching |
ANY_MALICIOUS_FINGERPRINT | Match any known malicious fingerprint |
ADWARE | Adware-associated fingerprints |
DRIDEX | Dridex malware fingerprints |
GOOTKIT | Gootkit malware fingerprints |
RANSOMWARE | Ransomware-associated fingerprints |
TRICKBOT | Trickbot malware fingerprints |
IP Threat Categories {#common-ip-threat-categories}
Section titled “IP Threat Categories {#common-ip-threat-categories}”IP address threat categories for security filtering.
| Value | Description |
|---|---|
SPAM_SOURCES | Known spam sources |
WINDOWS_EXPLOITS | Windows exploit sources |
WEB_ATTACKS | Web attack sources |
BOTNETS | Known botnet IPs |
SCANNERS | Network scanner IPs |
REPUTATION | Poor reputation IPs |
PHISHING | Phishing-related IPs |
PROXY | Anonymous proxy IPs |
MOBILE_THREATS | Mobile threat sources |
TOR_PROXY | Tor exit nodes |
DENIAL_OF_SERVICE | DoS attack sources |
NETWORK | Known bad network ranges |