Skip to content

Supported Resources Reference

The F5 Distributed Cloud Tools extension supports 236+ resource types across 25 F5 Distributed Cloud (XC) API domains. Resources are grouped by functional categories in the Explorer tree view.

1. Load Balancing and Application Delivery

Section titled “1. Load Balancing and Application Delivery”

Provides traffic distribution, protocol termination, and backend server pooling:

  • http_loadbalancer: HTTP/HTTPS virtual host proxies with automatic certificate management, routing rules, and security attachments. (Supports Describe, Edit, Diff, Access Logs, Metrics, Topology Diagrams).
  • tcp_loadbalancer: Layer 4 TCP proxy load balancing. (Supports Describe, Edit, Diff, Access Logs, Metrics).
  • udp_loadbalancer: Layer 4 UDP datagram distribution. (Supports Describe, Edit, Diff, Metrics).
  • origin_pool: Upstream backend target groups with health monitor associations and load balancing algorithms. (Supports Describe, Edit, Diff, Metrics).
  • healthcheck: Active health probes (HTTP, HTTPS, TCP) monitoring backend origin server availability. (Supports Form Builder, Describe, Edit, Diff).
  • route: Standalone Layer 7 routing rules and path matchers.
  • cdn_loadbalancer: Content Delivery Network edge caching and acceleration proxies.

Enforces Layer 7 application security, access control, and threat defense:

  • app_firewall: Web Application Firewall (WAF) policies with signature inspection, threat campaigning, and blocking modes.
  • service_policy: Declarative Layer 7 access control policies evaluating client IP, headers, paths, and cryptographic signatures.
  • rate_limiter_policy: Traffic shaping and threshold enforcement per client, IP prefix, or header.
  • user_identification: Client identity tracking rules extracting user identifiers from headers, cookies, or query parameters.
  • api_definition / api_protection: OpenAPI specification enforcement, shadow API discovery, and endpoint validation.
  • bot_defense_policy: Automated bot detection, behavioral analysis, and mitigation challenges.
  • ip_prefix_set: Reusable collections of IPv4 and IPv6 network prefixes.

Manages software-defined networking, site interconnects, and routing:

  • virtual_network: Site-local and global Layer 3 overlay networks.
  • network_connector: Interconnects between virtual networks, cloud environments, and physical interfaces.
  • network_policy: Layer 3/Layer 4 stateful firewall rules between virtual networks and endpoints.
  • bgp / bgp_routing_policy: Border Gateway Protocol peering configurations and route distribution filters.
  • route_table: Custom routing tables controlling next-hop transit across virtual networks.

Deploys and manages distributed Edge infrastructure across clouds and data centers:

  • site / aws_vpc_site / azure_vnet_site / gcp_vpc_site: Automated customer Edge sites deployed on bare metal or cloud providers.
  • virtual_site: Logical groupings of sites matching selector labels (e.g. ves.io/siteName in (us-east-1, us-west-2)).
  • cloud_credentials: Cloud provider authentication credentials (AWS IAM, Azure Service Principal, GCP Service Account) for automated site provisioning.
  • fleet: Distributed fleet management clusters managing software rollout and device configurations.

Configures authoritative DNS zones and global load balancing:

  • dns_zone: Authoritative Primary and Secondary DNS zones.
  • dns_load_balancer: Global server load balancing (GSLB) directing DNS queries based on geolocation, latency, or pool health.
  • dns_zone_record_set: Individual DNS record definitions (A, AAAA, CNAME, TXT, MX, SRV).

Configures log shipping, metrics export, and alerting policies:

  • log_receiver: Real-time log export pipelines forwarding telemetry to external SIEM/observability systems (Splunk, Datadog, AWS S3, HTTPS webhook).
  • alert_policy / alert_receiver: Notification channels and alerting thresholds.

Manages tenant access, roles, and credentials:

  • Namespaces (namespace) — Multi-tenant isolation boundaries.
  • Users and Roles (user, role) — Role-based access control (RBAC) permissions.
  • API Credentials (api_credential) — Service account and automated API token provisioning.
Resource TypeDescribeEdit (xcsh://)Diff (xcsh.fileDiff)Access LogsMetricsDiagram
http_loadbalancerYesYesYesYesYesYes
tcp_loadbalancerYesYesYesYesYes—
udp_loadbalancerYesYesYes—Yes—
origin_poolYesYesYes—Yes—
healthcheckYesYesYes———
app_firewallYesYesYes———
service_policyYesYesYes———
virtual_networkYesYesYes———
site / virtual_siteYesYesYes———
dns_zoneYesYesYes———
All other typesYesYesYes———