compute

PUT /v1/compute/servers/{serverId}/firewall

Replace a server's firewall rules.

所有 compute 端点

所有开发者文档

身份验证

请将 API 密钥作为 bearer 令牌发送。该密钥必须具有 sites.restart 权限;缺少该权限的密钥将被拒绝并返回 403 状态码,而非 404。

此端点不需要组织 ID。您的密钥已用于识别其所属的组织,且响应范围也仅限于该组织。

免费试用

将尖括号中的内容替换为您自己的值,并将键占位符替换为您仪表板中的一个键。

curl -X PUT https://api.zinndigital.com/v1/compute/servers/{serverId}/firewall \
  -H "Authorization: Bearer zdk_live_…" \
  -H "Content-Type: application/json" \
  -d '{ "rules": <ComputeFirewallRule[]> }'

已登录?您仪表板中的 API 控制台会自动填入您真实的组织 ID 和您自己的密钥,并针对实时 API 运行请求,以便您查看实际的响应。 在 API 控制台中打开此端点

详细信息

PUT, and the verb is the contract: this replaces the entire rule set. The provider's write is atomic, and an add/remove surface layered over an atomic replace is how two people editing at once discard each other's rule with both requests reporting success. ⛔⛔ This can lock the customer out of their own machine. A set with no inbound SSH is applied exactly as asked and their next connection is refused. That is why openComputeServerConsole exists, and why a client should say so beside this control. Refused when more than one firewall is applied to the machine: the effective policy is their union, so editing one and reporting the result would be false in the dangerous direction. The whole rule set is audit-logged, not a count — when a customer reports being locked out, "12 rules were set" answers nothing. Requires sites.restart.

参数

名称类型必填内容简介
serverId (path)UuidThe server's id, as listComputeServers reports it. Ours (UUIDv7), minted when the order row was written — never the provider's own identifier for the machine.

请求正文

名称类型必填内容简介
rulesComputeFirewallRule[]

响应

名称类型必填内容简介
idstringThe provider's firewall id
namestringIts name at the provider
attachedbooleanWhether a firewall resource is actually applied to this machine.
rulesComputeFirewallRule[]

此端点可能返回的错误

401 · 403 · 404 · 422 · 429 · 503