# NetworkBoundaries Object

> Source: https://truto.one/docs/api-reference/unified-cloud-infrastructure-api/networkboundaries/

Schema for the `NetworkBoundaries` resource in **Unified Cloud Infrastructure API**.

## Properties

- **`id`** _(string, required)_
  Truto's stable unified identifier for this object. Opaque; use provider_id to address the object in the provider's own console or API.
- **`provider_id`** _(string)_
  The provider's own identifier, passed through verbatim — a full ARN, resource id, or self-link. Never truncated, prefixed, or normalized.
- **`provider`** _(string)_
  Which cloud this object was read from.
  Allowed: `aws`, `azure`, `gcp`
- **`account`** _(string)_
  The account, subscription or project this object belongs to.
- **`region`** _(string)_
  Where the object is located. 'global' denotes genuinely global resources (e.g. IAM, GCP VPC networks) rather than a guessed region. A substituted region (when none is derivable) is flagged in unreadable_fields.
- **`native_type`** _(string)_
  The provider's own type string, unmodified — for example 'AWS::S3::Bucket', 'aws_iam_role', 'Microsoft.Sql/servers'. Used for display and drill-down.
- **`tags`** _(object)_
  Key-value pairs exactly as the customer set them: no case folding, key/value normalization, or merging of separate provider concepts. An empty object means no tags; tags that could not be read appear in unreadable_fields instead.
- **`collected_at`** _(string)_
  When Truto actually read this object from the provider, in UTC ISO 8601 with the offset present — not the request time, and not a provider timestamp.
- **`updated_at`** _(string)_
  When the object was last modified at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`created_at`** _(string)_
  When the object was created at the provider, in UTC ISO 8601. Null when the provider does not record one - see unreadable_fields.
- **`unreadable_fields`** _(array<object>)_
  Fields on this object that could not be read, and why. An empty array means everything was read. Use this to tell a real value from a missing one.
  - **`field`** _(string)_
    The property on this resource that could not be read.
  - **`reason`** _(string)_
    Why the field could not be read. available_on_get: Not read on list to keep the list fast; call GET for this resource's id to get it.
    Allowed: `not_supported_by_provider`, `not_configured`, `permission_denied`, `not_collected`, `collection_error`, `partially_collected`, `available_on_get`
  - **`detail`** _(string)_
    Explanation of the reason, where one adds anything.
- **`remote_data`** _(object)_
  Raw data returned from the remote API call.
- **`boundary_id`** _(string)_
  The provider's own identifier for the network.
- **`name`** _(string)_
  The network name.
- **`scope_type`** _(string)_
  Whether the network is regional or genuinely global.
  Allowed: `regional`, `global`
- **`is_global`** _(boolean)_
  True where the provider's network has no location at all. When true, the envelope region carries the literal string 'global' rather than a guessed region.
- **`cidr_ranges`** _(array<string>)_
  The address ranges the network covers.
- **`is_provider_default`** _(boolean)_
  Whether this is the provider's automatically created default network.
- **`subnets`** _(array<object>)_
  Subnets inside this boundary. Nested because a subnet is only meaningful within its boundary.
  - **`subnet_id`** _(string)_
    The subnet's provider reference.
  - **`cidr`** _(string)_
    The address range of the subnet.
  - **`availability_zone`** _(string)_
    The zone the subnet sits in.
  - **`maps_public_ip_on_launch`** _(boolean)_
    Whether instances launched here get a public IP automatically.
- **`attached_rule_sets`** _(array<object>)_
  Firewall rule sets attached at the boundary level.
  - **`id`** _(string)_
    The target's `id`.
- **`flow_logs_enabled`** _(boolean)_
  Whether flow logging is on for this boundary. Flow logs can attach at boundary, subnet, or interface level; true requires the log to be ACTIVE and actually delivering, not just present.
- **`flow_log_aggregation_interval_seconds`** _(integer)_
  How long the provider batches records before writing them — a batching window, not a sampling fraction. Not the same as flow_log_sampling_rate.
- **`flow_log_sampling_rate`** _(number)_
  What fraction of traffic is captured, where the provider samples. Null with not_supported_by_provider on AWS, which has no sampling rate field or setting.
- **`has_route_to_internet`** _(boolean)_
  Whether the boundary can reach the internet, accounting for subnets implicitly associated with the main route table (not just explicit associations).
- **`internet_route_type`** _(string)_
  What kind of internet path exists — an internet gateway (inbound-capable) is a different finding from outbound-only NAT, and the two are kept distinct.
  Allowed: `none`, `internet_gateway`, `nat_only`, `ipv6_egress_only`, `unknown`
- **`block_public_access_state`** _(string)_
  Whether a boundary-wide public-access block overrides routing. A boundary can have an internet gateway route and still be unreachable because of this.

## Methods

- [GET /unified/cloud-infrastructure/network_boundaries](/docs/api-reference/unified-cloud-infrastructure-api/networkboundaries/list) — List Network boundaries
