# FirewallRuleSets Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/firewallrulesets/

Schema for the `FirewallRuleSets` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`rule_set_id`** _(string)_
  The provider's own identifier for the rule set.
- **`name`** _(string)_
  The rule set name.
- **`scope_type`** _(string)_
  Which firewall primitive this is — the primitives have different semantics and available fields.
  Allowed: `security_group`, `network_acl`, `firewall_policy`, `firewall_rule`, `unknown`
- **`is_stateful`** _(boolean)_
  Whether return traffic is implicitly allowed.
- **`supports_deny`** _(boolean)_
  Whether this primitive can express a deny at all. False for AWS security groups (allow-only), where the rule's 'allow' action is a structural constant, not read from the provider.
- **`is_ordered`** _(boolean)_
  Whether rule order determines evaluation. False for AWS security groups, an unordered set evaluated as a union — array position is not a priority.
- **`attached_to`** _(array<string>)_
  What this rule set is attached to, as provider references. Null for security groups, where attachment is not in the provider model.
- **`attached_boundary`** _(object)_
  The network boundary this rule set belongs to.
  - **`id`** _(string)_
    The target's `id`.
- **`observed_attachment_only`** _(boolean)_
  True when attached_to was observed from live interfaces rather than read from configuration — a point-in-time observation, not a stable config fact.
- **`rules`** _(array<object>)_
  The rules in this set. Shape varies by rule set kind: ordered network ACL rules carry rule_number, security group rules do not.
  - **`direction`** _(string)_
    Whether the rule governs inbound or outbound traffic.
  - **`action`** _(string)_
    Allow or deny. Always allow where the provider has no deny primitive.
  - **`protocol`** _(string)_
    The protocol, or a value meaning all protocols.
  - **`from_port`** _(integer)_
    Lowest port in the range. For ICMP this is the type, not a port.
  - **`to_port`** _(integer)_
    Highest port in the range. For ICMP this is the code, not a port.
  - **`all_ports`** _(boolean)_
    Whether the rule covers every port, making the port range meaningless.
  - **`port_semantics`** _(string)_
    How to read from_port and to_port: as ports, or as ICMP type and code.
  - **`icmp_type_and_code`** _(string)_
    The ICMP type and code, where the protocol is ICMP.
  - **`cidrs`** _(array<string>)_
    Address ranges the rule matches.
  - **`ipv6_cidrs`** _(array<string>)_
    IPv6 address ranges the rule matches. Kept separate from cidrs because a rule can carry both and the two are not interchangeable.
  - **`source_group_ids`** _(array<string>)_
    Other rule sets the rule matches, where the provider allows that.
  - **`prefix_list_ids`** _(array<string>)_
    Provider-managed address lists the rule matches.
  - **`rule_number`** _(integer)_
    Evaluation order, where the provider orders rules. Absent for unordered rule sets.
  - **`egress`** _(boolean)_
    Set by network ACLs to mark an outbound rule.
  - **`description`** _(string)_
    Free-text note carried on the rule.
- **`rule_count`** _(integer)_
  How many rules this set contains.
- **`descriptions_supported`** _(boolean)_
  Whether this primitive has a per-rule description field at all — distinct from a rule having no description. AWS security group rules have one; network ACL entries do not.
- **`has_open_ingress_from_anywhere`** _(boolean)_
  Whether any rule permits inbound traffic from the whole internet. Derived.

## Methods

- [GET /unified/cloud-infrastructure/firewall_rule_sets](/docs/api-reference/unified-cloud-infrastructure-api/firewallrulesets/list) — List Firewall rule sets
