FirewallRuleSets Object
Relationships
graph LR
FirewallRuleSets -->|"account"| Accounts
FirewallRuleSets -->|"attached_boundary"| NetworkBoundaries
Properties
Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
The network boundary this rule set belongs to.
The target's id.
What this rule set is attached to, as provider references. Null for security groups, where attachment is not in the provider model.
When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
Whether this primitive has a per-rule description field at all — distinct from a rule having no description. AWS security group rules have one; network ACL entries do not.
Whether any rule permits inbound traffic from the whole internet. Derived.
Whether rule order determines evaluation. False for AWS security groups, an unordered set evaluated as a union — array position is not a priority.
Whether return traffic is implicitly allowed.
The rule set name.
The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
True when attached_to was observed from live interfaces rather than read from configuration — a point-in-time observation, not a stable config fact.
Which cloud this object was read from.
awsazuregcp
The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
Raw data returned from the remote API call.
How many rules this set contains.
The provider's own identifier for the rule set.
The rules in this set. Shape varies by rule set kind: ordered network ACL rules carry rule_number, security group rules do not.
Allow or deny. Always allow where the provider has no deny primitive.
Whether the rule covers every port, making the port range meaningless.
Address ranges the rule matches.
Free-text note carried on the rule.
Whether the rule governs inbound or outbound traffic.
Set by network ACLs to mark an outbound rule.
Lowest port in the range. For ICMP this is the type, not a port.
The ICMP type and code, where the protocol is ICMP.
IPv6 address ranges the rule matches. Kept separate from cidrs because a rule can carry both and the two are not interchangeable.
How to read from_port and to_port: as ports, or as ICMP type and code.
Provider-managed address lists the rule matches.
The protocol, or a value meaning all protocols.
Evaluation order, where the provider orders rules. Absent for unordered rule sets.
Other rule sets the rule matches, where the provider allows that.
Highest port in the range. For ICMP this is the code, not a port.
Which firewall primitive this is — the primitives have different semantics and available fields.
security_groupnetwork_aclfirewall_policyfirewall_ruleunknown
Whether this primitive can express a deny at all. False for AWS security groups (allow-only), where the rule's 'allow' action is a structural constant, not read from the provider.
Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
Explanation of the reason, where one adds anything.
The property on this resource that could not be read.
Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
not_supported_by_providernot_configuredpermission_deniednot_collectedcollection_errorpartially_collectedavailable_on_get
When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.