Skip to content

Relationships

Schema relationships
graph LR
    FirewallRuleSets -->|"account"| Accounts
    FirewallRuleSets -->|"attached_boundary"| NetworkBoundaries

Properties

idstring
required·

Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.

accountstring

The account, subscription or project this object belongs to.

References: Accounts → id
attached_boundaryobject

The network boundary this rule set belongs to.

idstring

The target's id.

attached_tostring[]

What this rule set is attached to, as provider references. Null for security groups, where attachment is not in the provider model.

collected_atstring · date-time

When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.

created_atstring

When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.

descriptions_supportedboolean

Whether this primitive has a per-rule description field at all — distinct from a rule having no description. AWS security group rules have one; network ACL entries do not.

has_open_ingress_from_anywhereboolean

Whether any rule permits inbound traffic from the whole internet. Derived.

is_orderedboolean

Whether rule order determines evaluation. False for AWS security groups, an unordered set evaluated as a union — array position is not a priority.

is_statefulboolean

Whether return traffic is implicitly allowed.

namestring

The rule set name.

native_typestring

The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.

observed_attachment_onlyboolean

True when attached_to was observed from live interfaces rather than read from configuration — a point-in-time observation, not a stable config fact.

providerstring

Which cloud this object was read from.

Possible values:
awsazuregcp
provider_idstring

The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.

regionstring

Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.

remote_dataRecord<string, any>

Raw data returned from the remote API call.

rule_countinteger

How many rules this set contains.

rule_set_idstring

The provider's own identifier for the rule set.

rulesobject[]

The rules in this set. Shape varies by rule set kind: ordered network ACL rules carry rule_number, security group rules do not.

actionstring

Allow or deny. Always allow where the provider has no deny primitive.

all_portsboolean

Whether the rule covers every port, making the port range meaningless.

cidrsstring[]

Address ranges the rule matches.

descriptionstring

Free-text note carried on the rule.

directionstring

Whether the rule governs inbound or outbound traffic.

egressboolean

Set by network ACLs to mark an outbound rule.

from_portinteger

Lowest port in the range. For ICMP this is the type, not a port.

icmp_type_and_codestring

The ICMP type and code, where the protocol is ICMP.

ipv6_cidrsstring[]

IPv6 address ranges the rule matches. Kept separate from cidrs because a rule can carry both and the two are not interchangeable.

port_semanticsstring

How to read from_port and to_port: as ports, or as ICMP type and code.

prefix_list_idsstring[]

Provider-managed address lists the rule matches.

protocolstring

The protocol, or a value meaning all protocols.

rule_numberinteger

Evaluation order, where the provider orders rules. Absent for unordered rule sets.

source_group_idsstring[]

Other rule sets the rule matches, where the provider allows that.

to_portinteger

Highest port in the range. For ICMP this is the code, not a port.

scope_typestring

Which firewall primitive this is — the primitives have different semantics and available fields.

Possible values:
security_groupnetwork_aclfirewall_policyfirewall_ruleunknown
supports_denyboolean

Whether this primitive can express a deny at all. False for AWS security groups (allow-only), where the rule's 'allow' action is a structural constant, not read from the provider.

tagsobject

Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.

unreadable_fieldsobject[]

Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.

detailstring

Explanation of the reason, where one adds anything.

fieldstring

The property on this resource that could not be read.

reasonstring

Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.

Possible values:
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
updated_atstring

When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.